CVE-2020-9967
Last modified
CVE-2020-9967 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. EPSS estimates a 2.32% chance of exploitation in the next 30 days.
Description
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Ipados | < 14.0 |
| Apple | Iphone Os | < 14.0 |
| Apple | Mac Os X | >= 10.14, < 10.14.6 |
| Apple | Mac Os X | >= 10.15, < 10.15.7 |
| Apple | Mac Os X | 10.14.6 |
| Apple | Mac Os X | 10.15.7 |
| Apple | Macos | >= 11.0, < 11.1.0 |
| Apple | Tvos | < 14.0 |
| Apple | Watchos | < 7.0 |
References
- http://packetstormsecurity.com/files/163501/XNU-Network-Stack-Kernel-Heap-Overflow.htmlThird Party Advisory, VDB Entry
- https://support.apple.com/en-us/HT211843Vendor Advisory
- https://support.apple.com/en-us/HT211844Vendor Advisory
- https://support.apple.com/en-us/HT211850Vendor Advisory
- https://support.apple.com/en-us/HT211931Vendor Advisory
- https://support.apple.com/en-us/HT212011Vendor Advisory
- http://packetstormsecurity.com/files/163501/XNU-Network-Stack-Kernel-Heap-Overflow.htmlThird Party Advisory, VDB Entry
- https://support.apple.com/en-us/HT211843Vendor Advisory
- https://support.apple.com/en-us/HT211844Vendor Advisory
- https://support.apple.com/en-us/HT211850Vendor Advisory
- https://support.apple.com/en-us/HT211931Vendor Advisory
- https://support.apple.com/en-us/HT212011Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9967?
How severe is CVE-2020-9967?
How do I fix CVE-2020-9967?
Are you affected by CVE-2020-9967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
