CVE-2020-9849

Description

An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0. A remote attacker may be able to leak memory.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.069

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Apple iTunes (X64) (12.10.9.3)Windows
Multiple vulnerabilities fixed in Apple iTunes (12.10.9.3)Windows
Multiple vulnerabilities fixed in iCloud 11.5Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 12.9.6Windows
Multiple Vulnerabilities are affected in Apple iTunes 12.9.6Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 12.10.8Windows
Multiple Vulnerabilities are affected in Apple iTunes 12.10.8Windows
Vulnerabilities CVE-2020-9849,CVE-2020-9876,CVE-2020-9961,CVE-2020-9999 are affected in Apple iTunes For Mac 12.10.8Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 12.10.8Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-316017Apple iTunes (X64) (12.10.9.3)
PATCH-316016Apple iTunes (12.10.9.3)
PATCH-316162iCloud (7.21.0.23) (Deployment-Only)
PATCH-310919Apple iTunes (X64) (12.10.0.7)
PATCH-310917Apple iTunes (12.10.0.7)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234