CVE-2020-3878: Input Validation
ImageIO. An out-of-bounds read was addressed with improved input validation.
Other sources
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9827
- CVE-2020-9842
- CVE-2020-9815
- CVE-2020-9791
- CVE-2020-9829
- CVE-2020-9816
- CVE-2020-3878
- CVE-2020-9789
- CVE-2020-9790
- CVE-2020-9837
- CVE-2020-9821
- CVE-2020-9797
- CVE-2020-9852
- CVE-2020-9795
- CVE-2020-9808
- CVE-2020-9811
- CVE-2020-9812
- CVE-2020-9813
- CVE-2020-9814
- CVE-2020-9809
- CVE-2020-9994
- CVE-2014-9512
- CVE-2020-9854
- CVE-2020-9794
- CVE-2020-9839
- CVE-2020-9805
- CVE-2020-9802
- CVE-2020-9850
- CVE-2020-9843
- CVE-2020-9803
- CVE-2020-9806
- CVE-2020-9807
- CVE-2020-9800
- CVE-2019-20503
- CVE-2020-3857
- CVE-2020-3855
- CVE-2020-3826
- CVE-2020-3870
- CVE-2020-3880
- CVE-2020-3837
- CVE-2019-8836
- CVE-2020-3840
- CVE-2020-3875
- CVE-2020-3872
- CVE-2020-3836
- CVE-2020-3842
- CVE-2020-3853
- CVE-2020-3846
- CVE-2020-3856
- CVE-2020-3829
- CVE-2020-3825
- CVE-2020-3868
- CVE-2020-3862
- CVE-2020-3867
- CVE-2020-3865
- CVE-2020-3864
- CVE-2020-3838
- CVE-2020-9772
- CVE-2020-9826
- CVE-2020-9804
- CVE-2020-9831
- CVE-2020-9779
- CVE-2020-3882
- CVE-2020-9828
- CVE-2020-9856
- CVE-2020-9847
- CVE-2020-9855
- CVE-2020-9822
- CVE-2020-9796
- CVE-2019-14868
- CVE-2020-9857
- CVE-2020-9817
- CVE-2020-9851
- CVE-2020-9793
- CVE-2020-9825
- CVE-2020-9771
- CVE-2020-9788
- CVE-2020-9824
- CVE-2020-9810
- CVE-2020-9792
- CVE-2020-9844
- CVE-2020-9830
- CVE-2020-9834
- CVE-2020-9833
- CVE-2020-9832
- CVE-2020-9841
- CVE-2019-20044
- CVE-2020-3877
- CVE-2019-11043
- CVE-2020-3866
- CVE-2020-3848
- CVE-2020-3849
- CVE-2020-3850
- CVE-2020-3847
- CVE-2020-3835
- CVE-2020-3863
- CVE-2020-9774
- CVE-2020-3827
- CVE-2020-3845
- CVE-2020-3851
- CVE-2020-3871
- CVE-2020-3830
- CVE-2020-3854
- CVE-2019-18634
- CVE-2020-3839
- CVE-2020-3843
- CVE-2020-9819
- CVE-2020-9818
- CVE-2020-3834
- CVE-2020-3860
- CVE-2020-6616
- CVE-2020-9838
- CVE-2020-9835
- CVE-2020-9820
- CVE-2020-9823
- CVE-2020-9848
- CVE-2020-3869
- CVE-2020-3858
- CVE-2020-3831
- CVE-2020-3873
- CVE-2020-3859
- CVE-2020-3844
- CVE-2020-3828
- CVE-2020-3841
- CVE-2020-3874
Frequently Asked Questions
What is CVE-2020-3878?
CVE-2020-3878 is a vulnerability in ImageIO where an out-of-bounds read was addressed with improved input validation.
What software is affected by CVE-2020-3878?
The software affected by CVE-2020-3878 includes Apple iCloud for Windows (up to version 11.2), iTunes for Windows (up to version 12.10.7), macOS Catalina (up to version 10.15.5), Mojave, High Sierra, watchOS (up to version 6.2.5), tvOS (up to version 13.4.5), iOS (up to version 13.5), and iPadOS (up to version 13.5).
How severe is CVE-2020-3878?
The severity of CVE-2020-3878 is not mentioned in the provided information.
How can I fix CVE-2020-3878?
To fix CVE-2020-3878, you should update the affected software to the latest version provided by Apple.
Where can I find more information about CVE-2020-3878?
You can find more information about CVE-2020-3878 on the Apple support website using the provided references: [link1], [link2], [link3].