CVE-2020-3866
https://notcve.org/view.php?id=CVE-2020-3866
This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Catalina 10.15.3. Searching for and opening a file from an attacker controlled NFS mount may bypass Gatekeeper. Esto se abordó con unas comprobaciones adicionales mediante Gatekeeper en los archivos montados por medio de una red compartida. Este problema está corregido en MacOS Catalina versión 10.15.3. • https://support.apple.com/HT210919 •
CVE-2020-3839 – Apple macOS IO80211Family Stack-based Buffer Overflow Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-3839
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory. Se abordó un problema de comprobación con un saneamiento de entrada mejorado. Este problema es corregido en macOS Catalina versión 10.15.3. • https://support.apple.com/HT210919 • CWE-20: Improper Input Validation •
CVE-2020-3849
https://notcve.org/view.php?id=CVE-2020-3849
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. Se abordó un problema de corrupción de la memoria con una comprobación de entrada mejorada. Este problema es corregido en macOS Catalina versión 10.15.3. • https://support.apple.com/HT210919 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •
CVE-2020-3830
https://notcve.org/view.php?id=CVE-2020-3830
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.3. A malicious application may be able to overwrite arbitrary files. Se presentó un problema de comprobación en el manejo de enlaces simbólicos. • https://support.apple.com/HT210919 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2020-3840
https://notcve.org/view.php?id=CVE-2020-3840
An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1. Loading a maliciously crafted racoon configuration file may lead to arbitrary code execution. Se presentó un problema por un paso en el manejo de los archivos de configuración racoon. • https://support.apple.com/HT210918 https://support.apple.com/HT210919 https://support.apple.com/HT210920 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-193: Off-by-one Error •