CVE-2020-3870: Input Validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. Processing a maliciously crafted image may lead to arbitrary code execution.
Other sources
ImageIO. An out-of-bounds read was addressed with improved input validation.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-3857
- CVE-2020-3855
- CVE-2020-3826
- CVE-2020-3870
- CVE-2020-3878
- CVE-2020-3880
- CVE-2020-3837
- CVE-2019-8836
- CVE-2020-3840
- CVE-2020-3875
- CVE-2020-3872
- CVE-2020-3836
- CVE-2020-3842
- CVE-2020-3853
- CVE-2020-3846
- CVE-2020-3856
- CVE-2020-3829
- CVE-2020-3825
- CVE-2020-3868
- CVE-2020-3862
- CVE-2020-3867
- CVE-2020-3865
- CVE-2020-3864
- CVE-2020-3838
- CVE-2020-3877
- CVE-2019-11043
- CVE-2020-3866
- CVE-2020-3848
- CVE-2020-3849
- CVE-2020-3850
- CVE-2020-3847
- CVE-2020-3835
- CVE-2020-3863
- CVE-2020-9774
- CVE-2020-3827
- CVE-2020-3845
- CVE-2020-3851
- CVE-2020-3871
- CVE-2020-3830
- CVE-2020-3854
- CVE-2019-18634
- CVE-2020-3839
- CVE-2020-3843
- CVE-2020-3834
- CVE-2020-3860
- CVE-2020-3869
- CVE-2020-3858
- CVE-2020-3831
- CVE-2020-3873
- CVE-2020-3859
- CVE-2020-3844
- CVE-2020-3828
- CVE-2020-3841
- CVE-2020-3874
Frequently Asked Questions
What is CVE-2020-3870?
CVE-2020-3870 is a vulnerability in ImageIO that allows an attacker to read out-of-bounds memory.
How does CVE-2020-3870 impact Apple watchOS?
CVE-2020-3870 impacts Apple watchOS 6.1.2 and earlier versions.
How does CVE-2020-3870 impact Apple tvOS?
CVE-2020-3870 impacts Apple tvOS 13.3.1 and earlier versions.
How does CVE-2020-3870 impact Apple iOS?
CVE-2020-3870 impacts Apple iOS 13.3.1 and earlier versions.
How does CVE-2020-3870 impact Apple iPadOS?
CVE-2020-3870 impacts Apple iPadOS 13.3.1 and earlier versions.
How does CVE-2020-3870 impact Apple macOS Catalina?
CVE-2020-3870 impacts Apple macOS Catalina 10.15.3 and earlier versions.
How does CVE-2020-3870 impact Apple Mojave?
There is no specific impact of CVE-2020-3870 mentioned for Apple Mojave, but it is recommended to apply necessary updates and patches.
How does CVE-2020-3870 impact Apple High Sierra?
There is no specific impact of CVE-2020-3870 mentioned for Apple High Sierra, but it is recommended to apply necessary updates and patches.
How do I fix CVE-2020-3870 on Apple devices?
To fix CVE-2020-3870, Apple has released the necessary updates and patches for affected devices, so make sure to update to the latest versions available.
What is the severity of CVE-2020-3870?
The severity of CVE-2020-3870 is not mentioned, but it is a vulnerability that should be addressed by applying the recommended updates.
Where can I find more information about CVE-2020-3870?
You can find more information about CVE-2020-3870 on the official Apple support page: [https://support.apple.com/en-us/HT210920](https://support.apple.com/en-us/HT210920)