exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Apple Security Advisory 2020-09-16-2

Apple Security Advisory 2020-09-16-2
Posted Sep 18, 2020
Authored by Apple | Site apple.com

Apple Security Advisory 2020-09-16-2 - tvOS 14.0 is now available and addresses cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
systems | apple
advisories | CVE-2020-9952, CVE-2020-9968, CVE-2020-9976, CVE-2020-9979
SHA-256 | 2c0cfb49a8acf362220ab9093a092bd0c1b1a10fe5bb67752992cccd85dde3e2

Apple Security Advisory 2020-09-16-2

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2020-09-16-2 tvOS 14.0

tvOS 14.0 is now available and addresses the following:

Assets
Available for: Apple TV 4K and Apple TV HD
Impact: An attacker may be able to misuse a trust relationship to
download malicious content
Description: A trust issue was addressed by removing a legacy API.
CVE-2020-9979: CodeColorist of Ant-Financial LightYear Labs

Keyboard
Available for: Apple TV 4K and Apple TV HD
Impact: A malicious application may be able to leak sensitive user
information
Description: A logic issue was addressed with improved state
management.
CVE-2020-9976: Rias A. Sherzad of JAIDE GmbH in Hamburg, Germany

Sandbox
Available for: Apple TV 4K and Apple TV HD
Impact: A malicious application may be able to access restricted
files
Description: A logic issue was addressed with improved restrictions.
CVE-2020-9968: Adam Chester(@xpn) of TrustedSec

WebKit
Available for: Apple TV 4K and Apple TV HD
Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack
Description: An input validation issue was addressed with improved
input validation.
CVE-2020-9952: Ryan Pickren (ryanpickren.com)

Additional recognition

Bluetooth
We would like to acknowledge Andy Davis of NCC Group and Dennis
Heinze (@ttdennis) of TU Darmstadt, Secure Mobile Networking Lab for
their assistance.

Core Location
We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for
their assistance.

iAP
We would like to acknowledge Andy Davis of NCC Group for their
assistance.

iBoot
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.

Kernel
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.

Location Framework
We would like to acknowledge an anonymous researcher for their
assistance.

Installation note:

Apple TV will periodically check for software updates. Alternatively,
you may manually check for software updates by selecting
"Settings -> System -> Software Update -> Update Software."

To check the current version of software, select
"Settings -> General -> About."
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAl9igrwACgkQZcsbuWJ6
jjC20Q//btHc0XNdZu1M133Uqeckujc3BdhVhImPTm4brg/OExquRj5vBKU+XsR0
vv439zYv3cJcxWPZIFoS3sHvm7B+PmGmBbgkhxwfRjejW93jBND9YjEywLfZchlB
07FuHf2eBbkURtxZ0sSPJ8zOMeAliIhFsjcstrPm2IqSNmtK2TUFCbAB7keZo2Zy
V5e9Zrktnmv4O024gTKKcFIJK7cmZNu7DSMxoKcarRemk6uAyRoOrixnlo7SWR68
Tik1TmSt86GzsaXtmxwFIywGa/Im95/gj0C1cCwkJVi/xwf+nWq0H5hhWCqOHJdx
hvjhVKizxZvmOewjO1wDNCZs5MdeRKs+GntG+2Qg7aCVWkz3fFVDGFo+2AIaGrq2
WjxtyQZHVLrGsg8+K5bxfB0cmcUyVJWS2hvM/vFn71ZUbC9OmINpHHqxyUqQ0yNu
O9QBC4crSyO9EQzrYJJjMlphWxYd4cQFQ+pinSy0P+Y0dev12qvWxC+aZiIOQ4rV
+bcgh9U4HfrF6sp0sZ/2wRmDLvQjxPJvdqhpjvrRRY2b9ohTQKqEw1P7RKEbMkZw
H4q/7H+5K7Z9nw388uhWxr6dRVVzz2jLzgefUetO6RlI5y0xeMqH8UwIAauQ62Gz
3p2iaZF84VNSETWDJXeAjRgbkSFIxnJERbnxntsLolb8BoWTsg0=
=TS1A
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close