First published: Tue Jan 28 2020(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution.
Credit: Samuel Groß Google Project ZeroCVE-2020-3870 Samuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project ZeroCVE-2020-3870 Samuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project ZeroCVE-2020-3870 Samuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project ZeroCVE-2020-3870 Samuel Groß Google Project ZeroSamuel Groß Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <13.3.1 | |
Apple iPhone OS | <13.3.1 | |
Apple Mac OS X | <10.15.3 | |
Apple tvOS | <13.3.1 | |
Apple watchOS | <6.1.2 | |
Apple tvOS | <13.3.1 | 13.3.1 |
Apple iOS | <13.3.1 | 13.3.1 |
Apple iPadOS | <13.3.1 | 13.3.1 |
Apple macOS Catalina | <10.15.3 | 10.15.3 |
Apple Mojave | ||
Apple High Sierra | ||
Apple watchOS | <6.1.2 | 6.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-3880 is a vulnerability in ImageIO that allows for an out-of-bounds read due to improved input validation.
CVE-2020-3880 affects Apple watchOS 6.1.2, Apple tvOS 13.3.1, Apple iOS 13.3.1, Apple iPadOS 13.3.1, Apple macOS Catalina 10.15.3, Apple Mojave, and Apple High Sierra.
The severity of CVE-2020-3880 is not specified.
To fix CVE-2020-3880, update your software to the latest version provided by Apple.
You can find more information about CVE-2020-3880 on Apple's official support pages: [link1](https://support.apple.com/en-us/HT210920), [link2](https://support.apple.com/en-us/HT210921), [link3](https://support.apple.com/en-us/HT210919).