CVE-2020-15358: Apple iCloud
Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Affected products
- Apple iCloud: before 7.21 (fixed in 7.21)
- Apple iPadOS: before 14.0 (fixed in 14.0)
- Apple iPhone OS: before 14.0 (fixed in 14.0)
- Apple macOS: before 11.0.1 (fixed in 11.0.1)
- Apple tvOS: before 14.0 (fixed in 14.0)
- Apple watchOS: before 7.0 (fixed in 7.0)
- Canonical Ubuntu Linux: version 20.04 only
- Oracle Communications Cloud Native Core Policy: version 1.14.0 only
- Oracle Communications Messaging Server: version 8.1 only
- Oracle Communications Network Charging And Control: version 6.0.1 only; version 12.0.2 only
- Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
- Oracle Hyperion Infrastructure Technology: version 11.1.2.4 only
- Oracle MySQL: up to and including 8.0.22
- Oracle Outside In Technology: version 8.5.4 only; version 8.5.5 only
- Siemens Sinec Infrastructure Network Services: before 1.0.1.1 (fixed in 1.0.1.1)
- Sqlite Sqlite: before 3.32.3 (fixed in 3.32.3)
Published 2020-06-27. Last modified 2026-06-17.