CVE-2020-3826
published 2020-02-27CVE-2020-3826: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.19%
64.6th percentile
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing a maliciously crafted image may lead to arbitrary code execution.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 11.0 | 11.0 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 11.0 | iCloud for Windows 11.0 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.17 | iCloud for Windows 7.17 |
| apple | ios | >= unspecified < iOS 13.3.1 and iPadOS 13.3.1 | iOS 13.3.1 and iPadOS 13.3.1 |
| apple | ipados | < 13.3.1 | 13.3.1 |
| apple | iphone_os | < 13.3.1 | 13.3.1 |
| apple | itunes | < 12.10.4 | 12.10.4 |
| apple | itunes_for_windows | >= unspecified < iTunes for Windows 12.10.4 | iTunes for Windows 12.10.4 |
| apple | mac_os_x | < 10.15.3 | 10.15.3 |
| apple | macos | >= unspecified < macOS Catalina 10.15.3 | macOS Catalina 10.15.3 |
| apple | tvos | < 13.3.1 | 13.3.1 |
| apple | tvos | >= unspecified < tvOS 13.3.1 | tvOS 13.3.1 |
| apple | watchos | < 6.1.2 | 6.1.2 |
| apple | watchos | >= unspecified < watchOS 6.1.2 | watchOS 6.1.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p5h3-5359-vcx7: An out-of-bounds read was addressed with improved input validation
ghsa_unreviewed·2022-05-24
CVE-2020-3826 [MEDIUM] GHSA-p5h3-5359-vcx7: An out-of-bounds read was addressed with improved input validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing a maliciously crafted image may lead to arbitrary code execution.
Project0
Fuzzing ImageIO - Project Zero
project_zero·2020-04-01
CVE-2020-11758 Fuzzing ImageIO - Project Zero
Posted by Samuel Groß, Project Zero
This blog post discusses an old type of issue, vulnerabilities in image format parsers, in a new(er) context: on interactionless code paths in popular messenger apps. This research was focused on the Apple ecosystem and the image parsing API provided by it: the ImageIO framework. Multiple vulnerabilities in image parsing code were found, reported to Apple or the respective open source image library maintainers, and subsequently fixed. During this research, a lightweight and low-overhead guided fuzzing approach for closed source binaries was implemented and is released alongside this blogpost.
To reiterate an important point, the vulnerabilities described throughout this blog are reachable through popular messengers but are not part of their codebase.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-27
Published