CVE-2020-9841 – Apple macOS SkyLight Integer Overflow Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2020-9841
An integer overflow was addressed through improved input validation. This issue is fixed in macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges. Se abordó un desbordamiento de enteros por medio de una comprobación de entrada mejorada. Este problema es corregido en macOS Catalina versión 10.15.5. • https://support.apple.com/HT211170 • CWE-190: Integer Overflow or Wraparound •
CVE-2020-9856 – Apple macOS Core Virtual Machine Service Heap-based Buffer Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2020-9856
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able to gain elevated privileges. Este problema se abordó con comprobaciones mejoradas. Este problema es corregido en macOS Catalina versión 10.15.5. • https://support.apple.com/HT211170 https://github.com/sslab-gatech/pwn2own2020 •
CVE-2020-9791 – Apple macOS AudioToolboxCore AIFF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-9791
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted audio file may lead to arbitrary code execution. Se abordó una lectura fuera de límites con una comprobación de entrada mejorada. Este problema es corregido en iOS versión 13.5 y iPadOS versión 13.5, macOS Catalina versión 10.15.5, tvOS versión 13.4.5, watchOS versión 6.2.5. • https://support.apple.com/HT211168 https://support.apple.com/HT211170 https://support.apple.com/HT211171 https://support.apple.com/HT211175 • CWE-125: Out-of-bounds Read •
CVE-2020-9816 – Apple macOS libFontParser Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-9816
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution. Se abordó un problema de escritura fuera de límites con una comprobación de límites mejorada. Este problema es corregido en iOS versión 13.5 y iPadOS versión 13.5, macOS Catalina versión 10.15.5, tvOS versión 13.4.5, watchOS versión 6.2.5. • https://support.apple.com/HT211168 https://support.apple.com/HT211170 https://support.apple.com/HT211171 https://support.apple.com/HT211175 • CWE-787: Out-of-bounds Write •
CVE-2020-6616
https://notcve.org/view.php?id=CVE-2020-6616
Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8 devices with the BCM4361 chipset. The Samsung ID is SVE-2020-16882 (May 2020). Algunos chips Broadcom manejan inapropiadamente la generación de números aleatorios de Bluetooth porque es usado un Pseudo Random Number Generator (PRNG) de baja entropía en situaciones en las que debería haberse utilizado un Hardware Random Number Generator (HRNG) para impedir la suplantación de identidad. Esto afecta, por ejemplo, a los dispositivos Samsung Galaxy S8, S8+ y Note8 con el chipset BCM4361. • http://bluetooth.lol http://seclists.org/fulldisclosure/2020/May/49 https://github.com/seemoo-lab/internalblue/blob/master/doc/rng.md https://media.ccc.de/v/DiVOC-6-finding_eastereggs_in_broadcom_s_bluetooth_random_number_generator https://security.samsungmobile.com/securityUpdate.smsb https://support.apple.com/HT211168 https://support.apple.com/kb/HT211100 https://support.apple.com/kb/HT211168 https://twitter.com/naehrdine/status/1255980443368919045 https://twitter.com/naehrdine/status/ •