MEDIUM
A logic issue was addressed with improved state management
Published Dec 8, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.41%
Description
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A local user may be able to read arbitrary files.
Affected products
-
Affected
- ≥ unspecified, < 14.2
-
Affected
- ≥ unspecified, < 11.0
- ≥ unspecified, < 11.5
- ≥ unspecified, < 12.11
-
Affected
- ≥ unspecified, < 14.2
-
Affected
- ≥ unspecified, < 7.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
OR
- < 11.5
- < 12.11
- < 14.2
- < 14.2
- < 11.0.1
- ≥ 10.14 · < 10.14.6
- ≥ 10.15 · < 10.15.7
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.15.7
- 10.15.7
- < 14.2
- < 7.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (10)
- http://seclists.org/fulldisclosure/2020/Dec/26 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/32 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-2467 Advisory
- https://support.apple.com/en-us/HT211928 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT211929 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT211930 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT211931 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT211933 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT211935 x_refsource_MISCVendor Advisory
- https://support.apple.com/kb/HT212011 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2020/Dec/26 | mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory | |
| http://seclists.org/fulldisclosure/2020/Dec/32 | mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-2467 | Advisory | |
| https://support.apple.com/en-us/HT211928 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT211929 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT211930 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT211931 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT211933 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT211935 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/kb/HT212011 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Dec 8, 2020
Updated Aug 4, 2024
Reserved Mar 2, 2020
Link CVE-2020-10002
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data