First published: Wed Jul 15 2020(Updated: )
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
Credit: Xingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntXingwei Lin AntMickey Jin Trend MicroXingwei Lin Ant product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13.4.8 | 13.4.8 |
macOS Catalina | <10.15.6 | 10.15.6 |
macOS Mojave | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Apple iCloud for Windows | <7.20 | |
Apple iCloud for Windows | >=10.0<11.3 | |
Apple iTunes for Windows | <12.10.8 | |
Apple iOS, iPadOS, and watchOS | <13.6 | |
iOS | <13.6 | |
Apple iOS and macOS | <10.15.6 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 | |
Apple iCloud | <7.20 | 7.20 |
Apple iCloud | <11.3 | 11.3 |
Apple iTunes | <12.10.8 | 12.10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2020-9874.
The title of the vulnerability is ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
The software products affected by this vulnerability include macOS Catalina (up to version 10.15.6), Apple Mojave, Apple High Sierra, Apple iOS (up to version 13.6), Apple iPadOS (up to version 13.6), Apple watchOS (up to version 6.2.8), Apple iCloud for Windows (up to version 7.20 or 11.3), Apple tvOS (up to version 13.4.8), and Apple iTunes for Windows (up to version 12.10.8).
The severity of CVE-2020-9874 is not specified.
To fix CVE-2020-9874, update to the latest available version of the affected software products as mentioned in the Apple security advisories (see references for more information).