CVE-2020-3894Race Condition in Apple Icloud FOR Windows

CWE-362Race Condition7 documents7 sources
Severity
3.1LOWNVD
EPSS
0.6%
top 29.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 24

Description

A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages11 packages

CVEListV5apple/icloud_for_windowsunspecifiediCloud for Windows 10.9.3+1
CVEListV5apple/itunes_for_windowsunspecifiediTunes for Windows 12.10.5
NVDapple/icloud< 10.9.3
CVEListV5apple/tvosunspecifiedtvOS 13.4
NVDapple/tvos< 13.4

🔴Vulnerability Details

3
GHSA
GHSA-86x5-95qc-wmgh: A race condition was addressed with additional validation2022-05-24
CVEList
CVE-2020-3894: A race condition was addressed with additional validation2020-04-01
OSV
CVE-2020-3894: A race condition was addressed with additional validation2020-04-01

📋Vendor Advisories

2
Red Hat
webkitgtk: Race condition allows reading of restricted memory2020-04-27
Debian
CVE-2020-3894: webkit2gtk - A race condition was addressed with additional validation. This issue is fixed i...2020

💬Community

1
Bugzilla
CVE-2020-3894 webkitgtk: Race condition allows reading of restricted memory2020-09-07
CVE-2020-3894 — Race Condition in Apple | cvebase