CERT-In Advisory
CIAD-2020-0079
Multiple Vulnerabilities in Apple High Sierra and Mojave
Original Issue Date: November 18, 2020
Severity Rating: High
Software Affected
- Apple macOS High Sierra versions prior to Safari 10.13.6
- Apple macOS Mojave versions prior to Safari 10.14.6
Overview
Multiple vulnerabilities have been reported in Apple High Sierra and Mojave which could allow an attacker to execute arbitrary code or disclose sensitive information on the target system.
Description
These vulnerabilities exist in Apple High Sierra and Mojave due to improper input validation, improper state handling issue or memory leakage issue. An attacker could exploit these vulnerabilities by executing a specially crafted application.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code or disclose kernel memory.
Solution
Apply appropriate patches as mentioned in the
Apple Security Updates
Vendor Information
Apple
https://support.apple.com/en-gb/HT211946
References
Apple
https://support.apple.com/en-gb/HT211946
CVE Name
CVE-2020-27930
CVE-2020-27932
CVE-2020-27950
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|