← Back

CVE-2020-3846

nvd nist
Published: Feb 27, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.

Affected (8)

7 products
Icloud
Ipados
Iphone Os
Itunes
Mac Os X
Tvos
Watchos
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Before 7.17
From 10.0 to 10.8
Before 13.3.1
Before 13.3.1
Before 12.10.4
Before 10.15.3
Before 13.3.1
Before 6.1.2

References (4)

Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.