CERT-In Advisory
CIAD-2020-0074
Multiple Vulnerabilities in Apple iOS and iPadOS
Original Issue Date: November 10, 2020
Severity Rating: High
Software Affected
- Apple iOS versions prior to 14.2
- Apple iPadOS versions prior to 14.2
- Apple iOS versions prior to 12.4.9(for iPhone 5s, iPhone 6 and 6 Plus, iPad Air, iPad mini 2 and 3, iPod touch 6th generation)
Overview
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could be exploited by an attacker to execute arbitrary code, gain elevated privileges, disclose sensitive information, bypass security restrictions or cause denial of service conditions on a targeted system.
Description
These vulnerabilities exist due to out-of-bounds read and write, use after free, type confusion, integer overflow,authentication, memory corruption, memory initialization and other logic issues in Audio, CallKit, CoreAudio, Crash Reporter, FaceTime, FontParser, Foundation, ImageIO, IOAcceleratorFamily, Kernel, Keyboard, libxml2, Logging, Model I/O and WebKit components of Apple iOS and iPadOS.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code, gain elevated privileges, disclose sensitive information, bypass security restrictions or cause denial of service conditions on the targeted system.
Solution
Apply appropriate updates as mentioned in the Apple Security Updates
https://support.apple.com/en-gb/HT201222
Vendor Information
Apple
https://support.apple.com/en-gb/HT211940
https://support.apple.com/en-gb/HT211929
References
CyberSecurityHelp
https://www.cybersecurity-help.cz/vdb/SB2020110605
https://www.cybersecurity-help.cz/vdb/SB2020110612
CVE Name
CVE-2020-10002
CVE-2020-10003
CVE-2020-10004
CVE-2020-10010
CVE-2020-10011
CVE-2020-10016
CVE-2020-10017
CVE-2020-13524
CVE-2020-27902
CVE-2020-27905
CVE-2020-27909
CVE-2020-27910
CVE-2020-27911
CVE-2020-27912
CVE-2020-27916
CVE-2020-27917
CVE-2020-27918
CVE-2020-27925
CVE-2020-27926
CVE-2020-27927
CVE-2020-27929
CVE-2020-27930
CVE-2020-27932
CVE-2020-27950
CVE-2020-9974
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|