CVE-2020-15358: Apple iCloud

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.

Affected products

  • Apple iCloud: before 7.21 (fixed in 7.21)
  • Apple iPadOS: before 14.0 (fixed in 14.0)
  • Apple iPhone OS: before 14.0 (fixed in 14.0)
  • Apple macOS: before 11.0.1 (fixed in 11.0.1)
  • Apple tvOS: before 14.0 (fixed in 14.0)
  • Apple watchOS: before 7.0 (fixed in 7.0)
  • Canonical Ubuntu Linux: version 20.04 only
  • Oracle Communications Cloud Native Core Policy: version 1.14.0 only
  • Oracle Communications Messaging Server: version 8.1 only
  • Oracle Communications Network Charging And Control: version 6.0.1 only; version 12.0.2 only
  • Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
  • Oracle Hyperion Infrastructure Technology: version 11.1.2.4 only
  • Oracle MySQL: up to and including 8.0.22
  • Oracle Outside In Technology: version 8.5.4 only; version 8.5.5 only
  • Siemens Sinec Infrastructure Network Services: before 1.0.1.1 (fixed in 1.0.1.1)
  • Sqlite Sqlite: before 3.32.3 (fixed in 3.32.3)

Published 2020-06-27. Last modified 2026-06-17.