CVE-2020-3868
published 2020-02-27CVE-2020-3868: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.70%
84.4th percentile
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.17 | 7.17 |
| apple | icloud | 10.0 – 10.8 | — |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 11.0 | iCloud for Windows 11.0 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.17 | iCloud for Windows 7.17 |
| apple | ios | >= unspecified < iOS 13.3.1 and iPadOS 13.3.1 | iOS 13.3.1 and iPadOS 13.3.1 |
| apple | ipados | < 13.3.1 | 13.3.1 |
| apple | iphone_os | < 13.3.1 | 13.3.1 |
| apple | itunes | < 12.10.4 | 12.10.4 |
| apple | itunes_for_windows | >= unspecified < iTunes for Windows 12.10.4 | iTunes for Windows 12.10.4 |
| apple | safari | < 13.0.5 | 13.0.5 |
| apple | safari | >= unspecified < Safari 13.0.5 | Safari 13.0.5 |
| apple | tvos | < 13.3.1 | 13.3.1 |
| apple | tvos | >= unspecified < tvOS 13.3.1 | tvOS 13.3.1 |
| debian | webkit2gtk | < webkit2gtk 2.26.4-1 (bookworm) | webkit2gtk 2.26.4-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.26.4-1 (bookworm) | webkit2gtk 2.26.4-1 (bookworm) |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whv5-w93h-96xh: Multiple memory corruption issues were addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2020-3868 [HIGH] CWE-119 GHSA-whv5-w93h-96xh: Multiple memory corruption issues were addressed with improved memory handling
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
OSV
CVE-2020-3868: Multiple memory corruption issues were addressed with improved memory handling
osv·2020-02-27·CVSS 8.8
CVE-2020-3868 [HIGH] CVE-2020-3868: Multiple memory corruption issues were addressed with improved memory handling
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2020-02-18
CVE-2020-3862 WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: Several security issues were fixed in WebKitGTK+.
A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
vendor_redhat·2020-02-14·CVSS 8.8
CVE-2020-3868 [HIGH] webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2020-3868: webkit2gtk - Multiple memory corruption issues were addressed with improved memory handling. ...
vendor_debian·2020·CVSS 8.8
CVE-2020-3868 [HIGH] CVE-2020-3868: webkit2gtk - Multiple memory corruption issues were addressed with improved memory handling. ...
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.26.4-1)
bullseye: resolved (fixed in 2.26.4-1)
forky: resolved (fixed in 2.26.4-1)
sid: resolved (fixed in 2.26.4-1)
trixie: resolved (fixed in 2.26.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-3868 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3868 [HIGH] CVE-2020-3868 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2020-3868 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2020-0002 describes the following issue:
CVE-2020-3868
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before 2.26.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0002.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
bugzilla·2019-02-14·CVSS 8.8
CVE-2019-7638 [HIGH] CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4500
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677144]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7638
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627
Bugzilla
CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c
bugzilla·2019-02-14·CVSS 8.1
CVE-2019-7636 [HIGH] CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c
CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4499
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677157]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7636
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-202
Bugzilla
CVE-2019-7635 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c
bugzilla·2019-02-14·CVSS 8.1
CVE-2019-7635 [HIGH] CVE-2019-7635 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c
CVE-2019-7635 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4498
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677159]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7635
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:46
Bugzilla
CVE-2019-7637 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c
bugzilla·2019-02-14·CVSS 8.8
CVE-2019-7637 [HIGH] CVE-2019-7637 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c
CVE-2019-7637 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4497
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677152]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7637
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA
Bugzilla
CVE-2019-7573 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7573 [HIGH] CVE-2019-7573 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
CVE-2019-7573 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the
wNumCoef loop).
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4491
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676752]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7573
---
This issue has been addressed in the following products:
Red Hat Enter
Bugzilla
CVE-2019-7576 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7576 [HIGH] CVE-2019-7576 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
CVE-2019-7576 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the
wNumCoef loop).
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4490
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676756]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7576
---
This issue has been addressed in the following products:
Red Hat Ente
Bugzilla
CVE-2019-7578 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.1
CVE-2019-7578 [HIGH] CVE-2019-7578 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c
CVE-2019-7578 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4494
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676782]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7578
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2
Bugzilla
CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7572 [HIGH] CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer
over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4495
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676754]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7572
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627 https:/
Bugzilla
CVE-2019-7575 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7575 [HIGH] CVE-2019-7575 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c
CVE-2019-7575 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4493
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676744]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7575
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA
Bugzilla
CVE-2019-7574 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7574 [HIGH] CVE-2019-7574 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c
CVE-2019-7574 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4496
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676750]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7574
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via
Bugzilla
CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
bugzilla·2019-02-12·CVSS 8.8
CVE-2019-7577 [HIGH] CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer
over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4492
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676510]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7577
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627 https://acc
Talos
Vulnerability Spotlight: Remote code execution vulnerability in Apple Safari
blogs_talos·2020-02-12·CVSS 8.8
[HIGH] Vulnerability Spotlight: Remote code execution vulnerability in Apple Safari
## Vulnerability Spotlight: Remote code execution vulnerability in Apple Safari
Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
The Apple Safari web browser contains a remote code execution vulnerability in its Fonts feature. If a user were to open a malicious web page in Safari, they could trigger a type confusion, resulting in memory corruption and possibly arbitrary code execution. An attacker would need to trick the user into visiting the web page by some means to trigger this vulnerability.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Apple to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details Apple Safari FontFaceSet remote code execution vulnera
Talos
Vulnerability Spotlight: Remote code execution vulnerability in Apple Safari
blogs_talos·2020-02-12·CVSS 8.8
[HIGH] Vulnerability Spotlight: Remote code execution vulnerability in Apple Safari
Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
The Apple Safari web browser contains a remote code execution vulnerability in its Fonts feature. If a user were to open a malicious web page in Safari, they could trigger a type confusion, resulting in memory corruption and possibly arbitrary code execution. An attacker would need to trick the user into visiting the web page by some means to trigger this vulnerability.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Apple to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsApple Safari FontFaceSet remote code execution vulnerability (TALOS-2019-0967/CVE-2020-3868)
A type confusion vulnerability exists in
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00004.htmlhttps://security.gentoo.org/glsa/202003-22https://support.apple.com/HT210920https://support.apple.com/HT210947https://support.apple.com/HT210948http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00004.htmlhttps://security.gentoo.org/glsa/202003-22https://support.apple.com/HT210920https://support.apple.com/HT210947https://support.apple.com/HT210948
2020-02-27
Published