CVE-2020-3880
published 2020-10-27CVE-2020-3880: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.33%
67.8th percentile
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | >= unspecified < 13.3 | 13.3 |
| apple | ipados | < 13.3.1 | 13.3.1 |
| apple | iphone_os | < 13.3.1 | 13.3.1 |
| apple | mac_os_x | < 10.15.3 | 10.15.3 |
| apple | macos | >= unspecified < 10.15 | 10.15 |
| apple | macos | >= unspecified < 13.3 | 13.3 |
| apple | macos | >= unspecified < 6.1 | 6.1 |
| apple | tvos | < 13.3.1 | 13.3.1 |
| apple | watchos | < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w7gc-5xjf-f39v: An out-of-bounds read was addressed with improved input validation
ghsa_unreviewed·2022-05-24
CVE-2020-3880 [HIGH] CWE-125 GHSA-w7gc-5xjf-f39v: An out-of-bounds read was addressed with improved input validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution.
Project0
Fuzzing ImageIO - Project Zero
project_zero·2020-04-01
CVE-2020-11758 Fuzzing ImageIO - Project Zero
Posted by Samuel Groß, Project Zero
This blog post discusses an old type of issue, vulnerabilities in image format parsers, in a new(er) context: on interactionless code paths in popular messenger apps. This research was focused on the Apple ecosystem and the image parsing API provided by it: the ImageIO framework. Multiple vulnerabilities in image parsing code were found, reported to Apple or the respective open source image library maintainers, and subsequently fixed. During this research, a lightweight and low-overhead guided fuzzing approach for closed source binaries was implemented and is released alongside this blogpost.
To reiterate an important point, the vulnerabilities described throughout this blog are reachable through popular messengers but are not part of their codebase.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT210918https://support.apple.com/en-us/HT210919https://support.apple.com/en-us/HT210920https://support.apple.com/en-us/HT210921https://support.apple.com/en-us/HT210918https://support.apple.com/en-us/HT210919https://support.apple.com/en-us/HT210920https://support.apple.com/en-us/HT210921
2020-10-27
Published