First published: Wed Jul 15 2020(Updated: )
ImageIO. An out-of-bounds read was addressed with improved input validation.
Credit: Xingwei Lin Antan anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13.4.8 | 13.4.8 |
macOS Catalina | <10.15.6 | 10.15.6 |
macOS Mojave | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Apple iCloud for Windows | <7.20 | |
Apple iCloud for Windows | >=10.0<11.3 | |
Apple iTunes for Windows | <12.10.8 | |
Apple iOS, iPadOS, and watchOS | <13.6 | |
iOS | <13.6 | |
Apple iOS and macOS | <10.15.6 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 | |
Apple iCloud | <11.3 | 11.3 |
Apple iCloud | <7.20 | 7.20 |
Apple iTunes | <12.10.8 | 12.10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-9873 refers to an out-of-bounds read vulnerability in ImageIO that has been addressed with improved input validation.
CVE-2020-9873 affects various software including macOS Catalina, Mojave, High Sierra, iOS, iPadOS, watchOS, iCloud for Windows, tvOS, and iTunes for Windows.
To fix CVE-2020-9873, you should update the affected software to the specific recommended versions provided by Apple.
You can find more information about CVE-2020-9873 on the official Apple support page.
The CWE ID for CVE-2020-9873 is 20, which corresponds to the weakness category of Improper Input Validation.