CVE-2020-3909: Buffer Overflow
libxml2. A buffer overflow was addressed with improved bounds checking.
Other sources
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Fixed in 10.15.4 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 6.2 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 7.18 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 10.9.3 - Upgrade
Upgrade
iTunesto a version that resolves this vulnerability.Fixed in 12.10.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iOS 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iPadOS 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in macOS Catalina 10.15.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in tvOS 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in watchOS 6.2 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iTunes for Windows 12.10.5 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iCloud for Windows 10.9.3 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iCloud for Windows 7.18
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3903
- CVE-2020-3904
- CVE-2020-3883
- CVE-2020-6616
- CVE-2020-9853
- CVE-2020-3907
- CVE-2020-3908
- CVE-2020-3912
- CVE-2020-9779
- CVE-2020-3892
- CVE-2020-3893
- CVE-2020-3905
- CVE-2019-8853
- CVE-2020-9776
- CVE-2020-9828
- CVE-2020-3913
- CVE-2020-9829
- CVE-2020-3898
- CVE-2020-3881
- CVE-2020-3886
- CVE-2019-14615
- CVE-2020-3919
- CVE-2020-3851
- CVE-2020-3896
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3884
- CVE-2020-3915
- CVE-2020-9775
- CVE-2020-9771
- CVE-2020-3918
- CVE-2019-19232
- CVE-2020-9786
- CVE-2020-3906
- CVE-2020-3889
- CVE-2020-9769
- CVE-2020-9787
- CVE-2020-3902
- CVE-2020-3917
- CVE-2020-9768
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3894
- CVE-2020-3899
- CVE-2020-3901
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3897
- CVE-2020-3885
- CVE-2020-3916
- CVE-2020-3891
- CVE-2020-9770
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3890
- CVE-2020-9781
- CVE-2020-3888
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-3909.
What software is affected by this vulnerability?
This vulnerability affects various Apple software including iOS, iPadOS, watchOS, iCloud for Windows, iTunes for Windows, macOS Catalina, Mojave, High Sierra, and tvOS.
What is the severity of CVE-2020-3909?
The severity of CVE-2020-3909 is not specified in the provided information.
Is there a fix available for CVE-2020-3909?
Yes, Apple has released patches to address this vulnerability. Please refer to the references for more information.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is 119.