First published: Wed Sep 16 2020(Updated: )
FontParser. A buffer overflow was addressed with improved size validation.
Credit: Yiğit Can YILMAZ @yilmazcanyigit Yiğit Can YILMAZ @yilmazcanyigit Yiğit Can YILMAZ @yilmazcanyigit Yiğit Can YILMAZ @yilmazcanyigit Yiğit Can YILMAZ @yilmazcanyigit product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.0.1 | 11.0.1 |
tvOS | <14.0 | 14.0 |
Apple macOS | <11.1 | 11.1 |
macOS Catalina | ||
macOS Mojave | ||
Apple iOS, iPadOS, and watchOS | <14.0 | |
iOS | <14.0 | |
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.7 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
Apple iOS and macOS | =10.14.6-security_update_2019-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-003 | |
Apple iOS and macOS | =10.14.6-security_update_2020-004 | |
Apple iOS and macOS | =10.14.6-security_update_2020-005 | |
Apple iOS and macOS | =10.14.6-security_update_2020-006 | |
Apple iOS and macOS | =10.14.6-supplemental_update | |
Apple iOS and macOS | =10.14.6-supplemental_update_2 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-supplemental_update | |
Apple iOS and macOS | >=11.0<11.0.1 | |
tvOS | <14.0 | |
Apple iOS, iPadOS, and watchOS | <7.0 | |
Apple iOS, iPadOS, and watchOS | <14.0 | 14.0 |
Apple iOS, iPadOS, and watchOS | <14.0 | 14.0 |
Apple iOS, iPadOS, and watchOS | <7.0 | 7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9962 is a vulnerability in FontParser that allows for a buffer overflow.
The severity of CVE-2020-9962 is medium.
CVE-2020-9962 affects Apple tvOS 14.0, Apple iOS 14.0, Apple iPadOS 14.0, Apple watchOS 7.0, Apple macOS Big Sur up to 11.0.1, Apple macOS Big Sur up to 11.1, Apple Catalina, and Apple Mojave.
To fix CVE-2020-9962, update to the latest version of the affected software provided by Apple.
You can find more information about CVE-2020-9962 on the Apple support website.