First published: Tue Jan 28 2020(Updated: )
ImageIO. An out-of-bounds read was addressed with improved input validation.
Credit: Samuel Groß Google Project ZeroCVE-2020-3870 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13.4.5 | 13.4.5 |
tvOS | <13.3.1 | 13.3.1 |
macOS Catalina | <10.15.5 | 10.15.5 |
macOS Mojave | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <13.5 | 13.5 |
Apple iOS, iPadOS, and watchOS | <13.5 | 13.5 |
Apple iOS, iPadOS, and watchOS | <13.3.1 | 13.3.1 |
Apple iOS, iPadOS, and watchOS | <13.3.1 | 13.3.1 |
Apple iOS, iPadOS, and watchOS | <6.2.5 | 6.2.5 |
Apple iOS, iPadOS, and watchOS | <6.1.2 | 6.1.2 |
Apple iCloud for Windows | <7.19 | |
Apple iCloud for Windows | >=11.0<11.2 | |
Apple iTunes for Windows | <12.10.7 | |
Apple iOS, iPadOS, and watchOS | <13.5 | |
iOS | <13.5 | |
Apple iOS and macOS | >=10.13<10.13.6 | |
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.5 | |
Apple iOS and macOS | =10.13.6 | |
Apple iOS and macOS | =10.13.6 | |
Apple iOS and macOS | =10.13.6-security_update_2018-002 | |
Apple iOS and macOS | =10.13.6-security_update_2018-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-001 | |
Apple iOS and macOS | =10.13.6-security_update_2019-002 | |
Apple iOS and macOS | =10.13.6-security_update_2019-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-004 | |
Apple iOS and macOS | =10.13.6-security_update_2019-005 | |
Apple iOS and macOS | =10.13.6-security_update_2019-006 | |
Apple iOS and macOS | =10.13.6-security_update_2019-007 | |
Apple iOS and macOS | =10.13.6-security_update_2020-001 | |
Apple iOS and macOS | =10.13.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
Apple iOS and macOS | =10.14.6-security_update_2019-002 | |
Apple iOS and macOS | =10.14.6-security_update_2019-004 | |
Apple iOS and macOS | =10.14.6-security_update_2019-005 | |
Apple iOS and macOS | =10.14.6-security_update_2019-006 | |
Apple iOS and macOS | =10.14.6-security_update_2019-007 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
tvOS | <13.4.5 | |
Apple iOS, iPadOS, and watchOS | <6.2.5 | |
Apple iCloud | <7.19 | 7.19 |
Apple iCloud | <11.2 | 11.2 |
Apple iTunes | <12.10.7 | 12.10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-3878 is a vulnerability in ImageIO where an out-of-bounds read was addressed with improved input validation.
The software affected by CVE-2020-3878 includes Apple iCloud for Windows (up to version 11.2), iTunes for Windows (up to version 12.10.7), macOS Catalina (up to version 10.15.5), Mojave, High Sierra, watchOS (up to version 6.2.5), tvOS (up to version 13.4.5), iOS (up to version 13.5), and iPadOS (up to version 13.5).
The severity of CVE-2020-3878 is not mentioned in the provided information.
To fix CVE-2020-3878, you should update the affected software to the latest version provided by Apple.
You can find more information about CVE-2020-3878 on the Apple support website using the provided references: [link1], [link2], [link3].