CVE-2021-30759: Input Validation
A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.
Other sources
ActionKit. An input validation issue was addressed with improved input validation.
— Apple
AMD Kernel. A memory corruption issue was addressed with improved input validation.
— Apple
Analytics. A logic issue was addressed with improved restrictions.
— Apple
Analytics. This issue was addressed with a new entitlement.
— Apple
App Store. A permissions issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30805
- CVE-2021-30871
- CVE-2021-30790
- CVE-2021-31006
- CVE-2021-30781
- CVE-2021-30748
- CVE-2021-30775
- CVE-2021-30776
- CVE-2021-30786
- CVE-2021-30772
- CVE-2021-30783
- CVE-2021-30777
- CVE-2021-30789
- CVE-2021-30774
- CVE-2021-30780
- CVE-2021-30768
- CVE-2021-30817
- CVE-2021-30804
- CVE-2021-30760
- CVE-2021-30788
- CVE-2021-30759
- CVE-2021-30803
- CVE-2021-30779
- CVE-2021-30785
- CVE-2021-30787
- CVE-2021-30766
- CVE-2021-30765
- CVE-2021-30784
- CVE-2021-30793
- CVE-2021-30778
- CVE-2021-30677
- CVE-2021-3518
- CVE-2021-30796
- CVE-2021-30792
- CVE-2021-30791
- CVE-2021-1821
- CVE-2021-30782
- CVE-2021-31004
- CVE-2021-30798
- CVE-2021-30758
- CVE-2021-30795
- CVE-2021-30797
- CVE-2021-30799
- CVE-2021-30773
- CVE-2021-30802
- CVE-2021-30769
- CVE-2021-30770
- CVE-2021-30811
- CVE-2021-30672
- CVE-2021-30733
- CVE-2021-30731
- CVE-2021-30703
- CVE-2021-30763
- CVE-2018-25010
- CVE-2018-25011
- CVE-2018-25014
- CVE-2020-36328
- CVE-2020-36329
- CVE-2020-36330
- CVE-2020-36331
- CVE-2021-30800
Frequently Asked Questions
What is CVE-2021-30759?
CVE-2021-30759 is a vulnerability in the FontParser component that allowed for a stack overflow, which has been addressed with improved input validation.
Which software versions are affected by CVE-2021-30759?
CVE-2021-30759 affects Apple Mojave, Apple WatchOS up to version 7.6, Apple tvOS up to version 14.7, Apple Catalina, and Apple macOS Big Sur up to version 11.5.
How severe is the CVE-2021-30759 vulnerability?
The severity of CVE-2021-30759 is not provided in the given information.
How can I fix the CVE-2021-30759 vulnerability?
To fix the CVE-2021-30759 vulnerability, make sure to update your software to the latest version provided by Apple.
Where can I find more information about CVE-2021-30759?
More information about CVE-2021-30759 can be found on the official Apple support website at the provided references.