First published: Wed Sep 16 2020(Updated: )
FontParser. An out-of-bounds read was addressed with improved input validation.
Credit: Mickey Jin Junzhi Lu Trend Micro Mobile Security Research Team working with Trend MicroMickey Jin Junzhi Lu Trend Micro Mobile Security Research Team working with Trend MicroMickey Jin Junzhi Lu Trend Micro Mobile Security Research Team working with Trend MicroMickey Jin Junzhi Lu Trend Micro Mobile Security Research Team working with Trend MicroMickey Jin Junzhi Lu Trend Micro Mobile Security Research Team working with Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.0.1 | 11.0.1 |
tvOS | <14.0 | 14.0 |
Apple macOS | <11.1 | 11.1 |
macOS Catalina | ||
macOS Mojave | ||
Apple iOS, iPadOS, and watchOS | <14.0. | |
iOS | <14.0 | |
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.7 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
Apple iOS and macOS | =10.14.6-security_update_2019-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-003 | |
Apple iOS and macOS | =10.14.6-security_update_2020-004 | |
Apple iOS and macOS | =10.14.6-security_update_2020-005 | |
Apple iOS and macOS | =10.14.6-security_update_2020-006 | |
Apple iOS and macOS | =10.14.6-supplemental_update | |
Apple iOS and macOS | =10.14.6-supplemental_update_2 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-supplemental_update | |
Apple iOS and macOS | >=11.0<11.1.0 | |
tvOS | <14.0 | |
Apple iOS, iPadOS, and watchOS | <7.0 | |
Apple iOS, iPadOS, and watchOS | <14.0 | 14.0 |
Apple iOS, iPadOS, and watchOS | <14.0 | 14.0 |
Apple iOS, iPadOS, and watchOS | <7.0 | 7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9956 is a vulnerability in FontParser that allows for an out-of-bounds read.
CVE-2020-9956 affects Apple devices running tvOS up to version 14.0, iOS up to version 14.0, iPadOS up to version 14.0, watchOS up to version 7.0, macOS Big Sur up to version 11.0.1, macOS Big Sur up to version 11.1, Catalina, and Mojave.
The severity of CVE-2020-9956 is not mentioned in the provided information.
To fix CVE-2020-9956, update your Apple device to the latest available version of the affected software.
You can find more information about CVE-2020-9956 at the following references: [Reference 1](https://support.apple.com/en-us/HT211843), [Reference 2](https://support.apple.com/en-us/HT212011), and [Reference 3](https://support.apple.com/en-us/HT211844).