CVE-2020-9994Apple Macos vulnerability

4 documents4 sources
Severity
7.1HIGHNVD
EPSS
0.3%
top 48.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 24

Description

A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to overwrite arbitrary files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages9 packages

CVEListV5apple/tvosunspecifiedtvOS 13.4.5
NVDapple/tvos< 13.4.5
CVEListV5apple/macosunspecifiedmacOS Catalina 10.15.5
NVDapple/ipados< 13.5
CVEListV5apple/watchosunspecifiedwatchOS 6.2.5

🔴Vulnerability Details

2
GHSA
GHSA-6cr6-65hv-4gh7: A path handling issue was addressed with improved validation2022-05-24
CVEList
CVE-2020-9994: A path handling issue was addressed with improved validation2020-10-22

📋Vendor Advisories

1
Apple
CVE-2020-9994: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra2020-07-15
CVE-2020-9994 — Apple Macos vulnerability | cvebase