CVE-2020-29624
Published on: 04/02/2021 12:00:00 AM UTC
Last Modified on: 06/28/2022 02:11:00 PM UTC
Certain versions of Ipados from Apple contain the following vulnerability:
A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font file may lead to arbitrary code execution.
- CVE-2020-29624 has been assigned by
product-sec[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Apple - iOS and iPadOS version < 14.3
- Affected Vendor/Software:
Apple - tvOS version < 14.3
- Affected Vendor/Software:
Apple - watchOS version < 7.2
- Affected Vendor/Software:
Apple - macOS version < 11.1
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
About the security content of tvOS 14.3 - Apple Support | support.apple.com text/html |
![]() |
About the security content of iOS 14.3 and iPadOS 14.3 - Apple Support | support.apple.com text/html |
![]() |
About the security content of watchOS 7.2 - Apple Support | support.apple.com text/html |
![]() |
About the security content of macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave - Apple Support | support.apple.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Operating System | Apple | Macos | All | All | All | All |
Operating System | Apple | Mac Os X | All | All | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | - | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2019-004 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2019-005 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2019-006 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2019-007 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2020-001 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2020-002 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2020-003 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2020-004 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2020-005 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | security_update_2020-006 | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | supplemental_update | All | All |
Operating System | Apple | Mac Os X | 10.14.6 | supplemental_update_2 | All | All |
Operating System | Apple | Mac Os X | 10.15.7 | - | All | All |
Operating System | Apple | Mac Os X | 10.15.7 | supplemental_update | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Watchos | All | All | All | All |
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-004:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-005:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-006:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-007:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-003:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-004:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-005:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-006:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:supplemental_update:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.14.6:supplemental_update_2:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os_x:10.15.7:supplemental_update:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2020-29624 : A memory corruption issue existed in the processing of font files. This issue was addressed with i… twitter.com/i/web/status/1… | 2021-04-02 18:23:57 |