Apple · Apple Macos · CVE-2020-10001
**Name of the Vulnerable Software and Affected Versions**
CUPS versions prior to the fixed version
macOS versions prior to Big Sur 11.1
macOS Catalina versions prior to Security Update 2020-001
macOS Mojave versions prior to Security Update 2020-007
**Description**
The issue is related to an input validation problem in the ippReadIO function of the cups/ipp.c component of the CUPS print server, which is associated with a lack of input data validation mechanism. This allows a remote attacker to gain access to confidential information. The problem was addressed with improved memory handling. A malicious application may be able to read restricted memory.
**Recommendations**
For CUPS, update to a version that includes the fix for the input validation issue.
For macOS Big Sur, update to version 11.1 or later.
For macOS Catalina, apply Security Update 2020-001 or later.
For macOS Mojave, apply Security Update 2020-007 or later.