CVE-2020-3882: Medium severity macos catalina vulnerability
Published May 26, 2020
·Updated
Calendar. This issue was addressed with improved checks.
Other sources
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously crafted calendar invitation may exfiltrate user information.
Credit
Andy Grant(NCC Group)
Affected Software
4 affected componentsFixes available
apple macOS Catalina<10.15.5
10.15.5
apple Mojave
apple High Sierra
Apple iOS and macOS<10.15.5
Event History
Jun 9, 2020
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9827
- CVE-2020-9772
- CVE-2020-9826
- CVE-2020-9842
- CVE-2020-9804
- CVE-2020-9815
- CVE-2020-9791
- CVE-2020-9831
- CVE-2020-9779
- CVE-2020-3882
- CVE-2020-9828
- CVE-2020-9856
- CVE-2020-9847
- CVE-2020-9855
- CVE-2020-9816
- CVE-2020-3878
- CVE-2020-9789
- CVE-2020-9790
- CVE-2020-9822
- CVE-2020-9796
- CVE-2020-9837
- CVE-2020-9821
- CVE-2020-9797
- CVE-2020-9852
- CVE-2020-9795
- CVE-2020-9808
- CVE-2020-9811
- CVE-2020-9812
- CVE-2020-9813
- CVE-2020-9814
- CVE-2020-9809
- CVE-2019-14868
- CVE-2020-9994
- CVE-2020-9857
- CVE-2020-9817
- CVE-2020-9851
- CVE-2020-9793
- CVE-2014-9512
- CVE-2020-9825
- CVE-2020-9771
- CVE-2020-9788
- CVE-2020-9854
- CVE-2020-9824
- CVE-2020-9810
- CVE-2020-9794
- CVE-2020-9839
- CVE-2020-9792
- CVE-2020-9844
- CVE-2020-9830
- CVE-2020-9834
- CVE-2020-9833
- CVE-2020-9832
- CVE-2020-9841
- CVE-2019-20044
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-3882.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability includes macOS Catalina (versions up to and exclusive of 10.15.5), Mojave, and High Sierra.
3
How was this vulnerability addressed?
This vulnerability was addressed with improved checks.
4
What is the severity of CVE-2020-3882?
The severity of CVE-2020-3882 is not provided.
5
How can I fix this vulnerability?
To fix this vulnerability, install the latest updates for macOS Catalina, Mojave, or High Sierra provided by Apple.