CVE-2020-3910: Buffer Overflow
libxml2. A buffer overflow was addressed with improved size validation.
Other sources
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Fixed in 10.15.4 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 6.2 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 10.9.3 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 7.18 - Upgrade
Upgrade
iTunesto a version that resolves this vulnerability.Fixed in 12.10.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iOS 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iPadOS 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in macOS Catalina 10.15.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in tvOS 13.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in watchOS 6.2 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iTunes for Windows 12.10.5 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iCloud for Windows 10.9.3 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in iCloud for Windows 7.18
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3903
- CVE-2020-3904
- CVE-2020-3883
- CVE-2020-6616
- CVE-2020-9853
- CVE-2020-3907
- CVE-2020-3908
- CVE-2020-3912
- CVE-2020-9779
- CVE-2020-3892
- CVE-2020-3893
- CVE-2020-3905
- CVE-2019-8853
- CVE-2020-9776
- CVE-2020-9828
- CVE-2020-3913
- CVE-2020-9829
- CVE-2020-3898
- CVE-2020-3881
- CVE-2020-3886
- CVE-2019-14615
- CVE-2020-3919
- CVE-2020-3851
- CVE-2020-3896
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3884
- CVE-2020-3915
- CVE-2020-9775
- CVE-2020-9771
- CVE-2020-3918
- CVE-2019-19232
- CVE-2020-9786
- CVE-2020-3906
- CVE-2020-3889
- CVE-2020-9769
- CVE-2020-9787
- CVE-2020-3902
- CVE-2020-3917
- CVE-2020-9768
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3894
- CVE-2020-3899
- CVE-2020-3901
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3897
- CVE-2020-3885
- CVE-2020-3916
- CVE-2020-3891
- CVE-2020-9770
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3890
- CVE-2020-9781
- CVE-2020-3888
Frequently Asked Questions
What is CVE-2020-3910?
CVE-2020-3910 is a vulnerability in libxml2 that allows for a buffer overflow due to inadequate size validation.
Which software versions are affected by CVE-2020-3910?
CVE-2020-3910 affects the following software versions: Apple iOS up to version 13.4, Apple iPadOS up to version 13.4, Apple watchOS up to version 6.2, Apple iTunes for Windows up to version 12.10.5, Apple iCloud for Windows up to version 10.9.3, Apple macOS Catalina up to version 10.15.4, Apple Mojave, Apple High Sierra, and Apple This document describes the security content of tvOS up to version 13.4.
What is the severity of CVE-2020-3910?
The severity of CVE-2020-3910 is not mentioned in the provided information. Please refer to the references for more details.
How can I fix CVE-2020-3910?
To fix CVE-2020-3910, it is recommended to update to the latest available version of the affected software. Please refer to the references for detailed remediation steps.
Where can I find more information about CVE-2020-3910?
You can find more information about CVE-2020-3910 in the provided references: [Reference 1](https://support.apple.com/en-us/HT211102), [Reference 2](https://support.apple.com/en-us/HT211103), [Reference 3](https://support.apple.com/en-us/HT211100).