Apple Security Advisories · April 2020 — Apple Security Advisories
11 advisories 11 CVEs

Apple-vendor CVEs for 2020-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2020-12243

OtherPoC exploitHIGH2020-04-28

In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).

CVEs:CVE-2020-12243

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-6203

tvOSPoC exploitCRITICAL2020-04-17

A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.

CVEs:CVE-2019-6203

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2020-11760

OtherEPSS <= 49%MEDIUM2020-04-14

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

CVEs:CVE-2020-11760

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11762

OtherEPSS <= 49%MEDIUM2020-04-14

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.

CVEs:CVE-2020-11762

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11758

OtherEPSS <= 49%MEDIUM2020-04-14

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

CVEs:CVE-2020-11758

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11763

OtherEPSS <= 49%MEDIUM2020-04-14

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

CVEs:CVE-2020-11763

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11761

OtherEPSS <= 49%MEDIUM2020-04-14

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.

CVEs:CVE-2020-11761

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11764

OtherEPSS <= 49%CRITICAL2020-04-14

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

CVEs:CVE-2020-11764

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11765

OtherEPSS <= 49%MEDIUM2020-04-14

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.

CVEs:CVE-2020-11765

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11759

OtherEPSS <= 49%CRITICAL2020-04-14

An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.

CVEs:CVE-2020-11759

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3898

macOSEPSS <= 49%CRITICAL2020-04-26

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.

CVEs:CVE-2020-3898

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.