CVE-2020-9967

high

Description

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

References

https://support.apple.com/en-us/HT212011

https://support.apple.com/en-us/HT211931

https://support.apple.com/en-us/HT211850

https://support.apple.com/en-us/HT211844

https://support.apple.com/en-us/HT211843

http://packetstormsecurity.com/files/163501/XNU-Network-Stack-Kernel-Heap-Overflow.html

Details

Source: Mitre, NVD

Published: 2021-04-02

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High