First published: Wed Jul 15 2020(Updated: )
ImageIO. An integer overflow was addressed through improved input validation.
Credit: Mickey Jin Trend MicroMickey Jin Trend MicroMickey Jin Trend MicroMickey Jin Trend MicroMickey Jin Trend MicroMickey Jin Trend MicroMickey Jin Trend MicroMickey Jin Trend MicroMickey Jin Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13.4.8 | 13.4.8 |
macOS Catalina | <10.15.6 | 10.15.6 |
macOS Mojave | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Apple iCloud for Windows | <7.20 | |
Apple iCloud for Windows | >=10.0<11.3 | |
Apple iTunes for Windows | <12.10.8 | |
Apple iOS, iPadOS, and watchOS | <13.6 | |
iOS | <13.6 | |
Apple iOS and macOS | <10.15.6 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 | |
Apple iCloud | <11.3 | 11.3 |
Apple iTunes | <12.10.8 | 12.10.8 |
Apple iCloud | <7.20 | 7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-9875 is a vulnerability in ImageIO where an integer overflow was addressed through improved input validation.
CVE-2020-9875 affects macOS Catalina 10.15.6, Mojave, High Sierra, iOS 13.6, iPadOS 13.6, watchOS 6.2.8, iCloud for Windows 7.20 and 11.3, tvOS 13.4.8, and iTunes for Windows 12.10.8.
To fix CVE-2020-9875, update your software to the recommended versions provided by Apple.
You can find more information about CVE-2020-9875 in the references provided by Apple.
The Common Weakness Enumeration (CWE) IDs for CVE-2020-9875 are CWE-20 and CWE-190.