CVE-2020-10011

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
appleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
appleipados
𝑥
< 14.2
appleiphone_os
𝑥
< 14.2
applemac_os_x
𝑥
< 10.13.6
applemac_os_x
10.14 ≤
𝑥
< 10.14.6
applemac_os_x
10.15 ≤
𝑥
< 10.15.7
applemac_os_x
11.0.0 ≤
𝑥
< 11.0.1
applemac_os_x
10.13.6
applemac_os_x
10.13.6:security_update_2018-002
applemac_os_x
10.13.6:security_update_2018-003
applemac_os_x
10.13.6:security_update_2019-001
applemac_os_x
10.13.6:security_update_2019-002
applemac_os_x
10.13.6:security_update_2019-003
applemac_os_x
10.13.6:security_update_2019-004
applemac_os_x
10.13.6:security_update_2019-005
applemac_os_x
10.13.6:security_update_2019-006
applemac_os_x
10.13.6:security_update_2019-007
applemac_os_x
10.13.6:security_update_2020-001
applemac_os_x
10.13.6:security_update_2020-002
applemac_os_x
10.13.6:security_update_2020-003
applemac_os_x
10.13.6:security_update_2020-004
applemac_os_x
10.14.6
applemac_os_x
10.14.6:security_update_2019-001
applemac_os_x
10.14.6:security_update_2019-002
applemac_os_x
10.14.6:security_update_2019-004
applemac_os_x
10.14.6:security_update_2019-005
applemac_os_x
10.14.6:security_update_2019-006
applemac_os_x
10.14.6:security_update_2019-007
applemac_os_x
10.14.6:security_update_2020-001
applemac_os_x
10.14.6:security_update_2020-002
applemac_os_x
10.14.6:security_update_2020-003
applemac_os_x
10.14.6:security_update_2020-004
applemac_os_x
11.0.1
appletvos
𝑥
< 14.2
𝑥
= Vulnerable software versions