First published: Tue Mar 24 2020(Updated: )
WebKit. A memory corruption issue was addressed with improved memory handling.
Credit: grigoritchy Dongzhuo Zhao ADLab of Venustechgrigoritchy Dongzhuo Zhao ADLab of Venustechgrigoritchy Dongzhuo Zhao ADLab of Venustechgrigoritchy Dongzhuo Zhao ADLab of Venustechgrigoritchy Dongzhuo Zhao ADLab of Venustechgrigoritchy Dongzhuo Zhao ADLab of Venustechgrigoritchy Dongzhuo Zhao ADLab of Venustech product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/webkitgtk | <2.28.0 | 2.28.0 |
Apple Mobile Safari | <13.1 | 13.1 |
Apple iCloud for Windows | <7.18 | |
Apple iCloud for Windows | >=10.0.0<10.9.3 | |
Apple iTunes for Windows | <12.10.5 | |
Apple Mobile Safari | <13.1 | |
iPadOS | <13.4 | |
iOS | <13.4 | |
tvOS | <13.4 | |
Apple iOS, iPadOS, and watchOS | <6.2 | |
tvOS | <13.4 | 13.4 |
Apple iOS, iPadOS, and watchOS | <13.4 | 13.4 |
Apple iOS, iPadOS, and watchOS | <13.4 | 13.4 |
Apple iOS, iPadOS, and watchOS | <6.2 | 6.2 |
Apple iCloud | <7.18 | 7.18 |
Apple iCloud | <10.9.3 | 10.9.3 |
Apple iTunes | <12.10.5 | 12.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2020-3900.
The affected software includes Apple Safari, Apple iOS, Apple iPadOS, Apple watchOS, Apple iCloud for Windows, Apple iTunes for Windows, and Apple tvOS.
The severity of CVE-2020-3900 has not been specified.
CVE-2020-3900 can lead to memory corruption, which could potentially allow an attacker to execute arbitrary code or cause a denial of service.
To fix CVE-2020-3900, it is recommended to update the affected software to the latest version provided by Apple.