CVE-2020-9967
published 2021-04-02CVE-2020-9967: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.32%
81.7th percentile
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | >= unspecified < 14.0 | 14.0 |
| apple | ipados | < 14.0 | 14.0 |
| apple | iphone_os | < 14.0 | 14.0 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.14 < 10.14.6 | 10.14.6 |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.1.0 | 11.1.0 |
| apple | macos | >= unspecified < 11.0 | 11.0 |
| apple | macos | >= unspecified < 11.1 | 11.1 |
| apple | tvos | < 14.0 | 14.0 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 14.0 | 14.0 |
| apple | watchos | < 7.0 | 7.0 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 7.0 | 7.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2020-9967: tvOS 14.0
vendor_apple·2020-09-16·CVSS 7.8
CVE-2020-9967 [HIGH] CVE-2020-9967: tvOS 14.0
Apple Security Update: About the security content of tvOS 14.0
Product: tvOS
Version: 14.0
CVE: CVE-2020-9967
Component: Kernel
Impact: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2020-9967: watchOS 7.0
vendor_apple·2020-09-16·CVSS 7.8
CVE-2020-9967 [HIGH] CVE-2020-9967: watchOS 7.0
Apple Security Update: About the security content of watchOS 7.0
Product: watchOS
Version: 7.0
CVE: CVE-2020-9967
Component: Kernel
Impact: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory
Description: Multiple memory corruption issues were addressed with improved input validation.
GHSA
GHSA-346j-g3cg-vw5q: Multiple memory corruption issues were addressed with improved input validation
ghsa_unreviewed·2022-05-24
CVE-2020-9967 [HIGH] CWE-119 GHSA-346j-g3cg-vw5q: Multiple memory corruption issues were addressed with improved input validation
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/163501/XNU-Network-Stack-Kernel-Heap-Overflow.htmlhttps://support.apple.com/en-us/HT211843https://support.apple.com/en-us/HT211844https://support.apple.com/en-us/HT211850https://support.apple.com/en-us/HT211931https://support.apple.com/en-us/HT212011http://packetstormsecurity.com/files/163501/XNU-Network-Stack-Kernel-Heap-Overflow.htmlhttps://support.apple.com/en-us/HT211843https://support.apple.com/en-us/HT211844https://support.apple.com/en-us/HT211850https://support.apple.com/en-us/HT211931https://support.apple.com/en-us/HT212011
2021-04-02
Published