CVE-2020-29619: Input Validation
ImageIO. An out-of-bounds read was addressed with improved input validation.
Other sources
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-29610
- CVE-2020-27948
- CVE-2020-29608
- CVE-2020-27946
- CVE-2020-27943
- CVE-2020-27944
- CVE-2020-29624
- CVE-2020-29615
- CVE-2020-29617
- CVE-2020-29619
- CVE-2020-29618
- CVE-2020-29611
- CVE-2020-29614
- CVE-2020-9972
- CVE-2020-29623
- CVE-2020-15969
- CVE-2021-31077
- CVE-2020-27914
- CVE-2020-27915
- CVE-2020-27936
- CVE-2020-27903
- CVE-2020-27941
- CVE-2020-29621
- CVE-2020-27910
- CVE-2020-9943
- CVE-2020-9944
- CVE-2020-27916
- CVE-2020-27906
- CVE-2020-27908
- CVE-2020-9960
- CVE-2020-10017
- CVE-2020-27922
- CVE-2020-10001
- CVE-2020-9962
- CVE-2020-27952
- CVE-2020-9956
- CVE-2020-27931
- CVE-2020-10002
- CVE-2020-27947
- CVE-2020-29612
- CVE-2020-9978
- CVE-2020-27939
- CVE-2020-29625
- CVE-2020-29616
- CVE-2020-27924
- CVE-2020-27912
- CVE-2020-27923
- CVE-2020-27919
- CVE-2020-10015
- CVE-2020-27897
- CVE-2020-27907
- CVE-2020-9974
- CVE-2020-10016
- CVE-2020-9967
- CVE-2020-9975
- CVE-2020-27921
- CVE-2020-27949
- CVE-2020-29620
- CVE-2020-27911
- CVE-2020-27920
- CVE-2020-27926
- CVE-2020-10014
- CVE-2020-10010
- CVE-2020-29633
- CVE-2020-13520
- CVE-2020-13524
- CVE-2020-10004
- CVE-2020-27901
- CVE-2020-27938
- CVE-2020-10007
- CVE-2020-10012
- CVE-2020-27896
- CVE-2020-10009
- CVE-2020-27898
- CVE-2020-27951
- CVE-2020-29613
Frequently Asked Questions
What is CVE-2020-29619?
CVE-2020-29619 is a vulnerability in ImageIO that allows for an out-of-bounds read, but it has been addressed with improved input validation.
Which software is affected by CVE-2020-29619?
CVE-2020-29619 affects Apple iOS (up to version 14.3), Apple iPadOS (up to version 14.3), Apple tvOS (up to version 14.3), Apple iCloud for Windows (up to version 12.0), Apple macOS Big Sur (up to version 11.1), Apple Catalina, Apple Mojave, and Apple watchOS (up to version 7.2).
How can I fix CVE-2020-29619?
To fix CVE-2020-29619, make sure you have the latest updates installed for the affected software versions of Apple iOS, Apple iPadOS, Apple tvOS, Apple iCloud for Windows, Apple macOS Big Sur, Apple Catalina, Apple Mojave, and Apple watchOS.
What is the severity of CVE-2020-29619?
The severity of CVE-2020-29619 is not specified.
Where can I find more information about CVE-2020-29619?
You can find more information about CVE-2020-29619 on the Apple Support website: [link](https://support.apple.com/en-us/HT212009), [link](https://support.apple.com/en-us/HT212003), [link](https://support.apple.com/en-us/HT212005).