cbcvebase.
CVE-2020-9994
published 2020-10-22

CVE-2020-9994: A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS…

high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to overwrite arbitrary files.

Affected

10 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.5 and iPadOS 13.5iOS 13.5 and iPadOS 13.5
appleipados< 13.513.5
appleiphone_os< 13.513.5
applemac_os_x< 10.15.510.15.5
applemacos>= unspecified < macOS Catalina 10.15.5macOS Catalina 10.15.5
applemacos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004
appletvos< 13.4.513.4.5
appletvos>= unspecified < tvOS 13.4.5tvOS 13.4.5
applewatchos< 6.2.56.2.5
applewatchos>= unspecified < watchOS 6.2.5watchOS 6.2.5