CERT-In Advisory
CIAD-2020-0004
Multiple Vulnerabilities in Apple iOS and iPadOS
Original Issue Date: January 30, 2020
Severity Rating: High
Software Affected
- Apple iOS and iPadOS versions prior to 13.3.1
Overview
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could allow a remote attacker to execute arbitrary code, access sensitive or privileged information, gain elevated privileges, cause memory corruption, cause denial of service conditions or perform cross site scripting attacks on a targeted system.
Description
These vulnerabilities exist due to multiple memory corruption issues, out-of-bounds read error, improper input sanitization, improper memory initialization and access, race condition, buffer overflow, type confusion, improper UI handling and other logical errors in Audio, FaceTime, ImageIO, IOAcceleratorFamily, IPSec, Kernel, libxml2, libxpc, Mail, Messages, Phone, Safari Login AutoFill, Screenshots, WebKit and wifivelocityd components of iOS and iPadOS.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code, access sensitive or privileged information, gain elevated privileges, cause memory corruption, cause denial of service conditions or perform cross site scripting attacks on a targeted system.
Solution
Upgrade Apple iOSand iPadOSas mentioned in the
Apple security updates.
Vendor Information
Apple
https://support.apple.com/en-in/HT210918
References
Apple
https://support.apple.com/en-in/HT210918
CVE Name
CVE-2020-3857
CVE-2020-3869
CVE-2020-3826
CVE-2020-3870
CVE-2020-3878
CVE-2020-3837
CVE-2020-3840
CVE-2020-3875
CVE-2020-3872
CVE-2020-3836
CVE-2020-3842
CVE-2020-3858
CVE-2020-3831
CVE-2020-3853
CVE-2020-3860
CVE-2020-3846
CVE-2020-3856
CVE-2020-3829
CVE-2020-3873
CVE-2020-3859
CVE-2020-3844
CVE-2020-3828
CVE-2020-3841
CVE-2020-3874
CVE-2020-3862
CVE-2020-3825
CVE-2020-3868
CVE-2020-3867
CVE-2020-3865
CVE-2020-3838
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|