CVE-2020-3898
published 2020-10-22CVE-2020-3898: A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.39%
31.7th percentile
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.3.1-12 | 2.3.1-12 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.11 | 2.1.3-4ubuntu0.11 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.8 | 2.2.7-1ubuntu2.8 |
| apple | cups | >= 0 < 2.3.1-9ubuntu1.1 | 2.3.1-9ubuntu1.1 |
| apple | mac_os_x | < 10.15.4 | 10.15.4 |
| apple | macos | >= unspecified < macOS Catalina 10.15.4 | macOS Catalina 10.15.4 |
| debian | cups | < cups 2.3.1-12 (bookworm) | cups 2.3.1-12 (bookworm) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2020-04-27·CVSS 5.5
CVE-2019-2228 [MEDIUM] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
It was discovered that CUPS incorrectly handled certain language values. A
local attacker could possibly use this issue to cause CUPS to crash,
leading to a denial of service, or possibly obtain sensitive information.
This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
19.10. (CVE-2019-2228)
Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed
ppd files. A local attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-3898)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c
vendor_redhat·2020-04-20·CVSS 7.8
CVE-2020-3898 [HIGH] CWE-125 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c
cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
Package: cups (Red Hat Enterprise Linux 5) - Out of support scope
Package: cups (Red Hat Enterprise Linux 6) - Out of support scope
Package: cups (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2020-3898: cups - A memory corruption issue was addressed with improved validation. This issue is ...
vendor_debian·2020·CVSS 7.8
CVE-2020-3898 [HIGH] CVE-2020-3898: cups - A memory corruption issue was addressed with improved validation. This issue is ...
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
Scope: local
bookworm: resolved (fixed in 2.3.1-12)
bullseye: resolved (fixed in 2.3.1-12)
forky: resolved (fixed in 2.3.1-12)
sid: resolved (fixed in 2.3.1-12)
trixie: resolved (fixed in 2.3.1-12)
GHSA
GHSA-82r2-pfjv-q743: A memory corruption issue was addressed with improved validation
ghsa_unreviewed·2022-05-24
CVE-2020-3898 [HIGH] CWE-119 GHSA-82r2-pfjv-q743: A memory corruption issue was addressed with improved validation
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
OSV
CVE-2020-3898: A memory corruption issue was addressed with improved validation
osv·2020-10-22·CVSS 7.8
CVE-2020-3898 [HIGH] CVE-2020-3898: A memory corruption issue was addressed with improved validation
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
OSV
cups vulnerabilities
osv·2020-04-27·CVSS 5.5
CVE-2019-2228 [MEDIUM] cups vulnerabilities
cups vulnerabilities
It was discovered that CUPS incorrectly handled certain language values. A
local attacker could possibly use this issue to cause CUPS to crash,
leading to a denial of service, or possibly obtain sensitive information.
This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
19.10. (CVE-2019-2228)
Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed
ppd files. A local attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-3898)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-4032 freerdp: integer casting vulnerability in update_recv_secondary_order
bugzilla·2020-07-08·CVSS 3.1
CVE-2020-4032 [LOW] CVE-2020-4032 freerdp: integer casting vulnerability in update_recv_secondary_order
CVE-2020-4032 freerdp: integer casting vulnerability in update_recv_secondary_order
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
References:
http://www.freerdp.com/2020/06/22/2_1_2-released
https://github.com/FreeRDP/FreeRDP/commit/e7bffa64ef5ed70bac94f823e2b95262642f5296
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3898-mc89-x2vc
Discussion:
Created freerdp tracking bugs for this issue:
Affects: epel-all [bug 1854873]
Affects: fedora-all [bug 1854872]
---
Mitigation:
Do not run the freerdp client with the +glyph-cache and /relax-order-checks options.
---
In libfreerdp/core/orders.c update_recv_secondary_order
Bugzilla
CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c [fedora-all]
bugzilla·2020-04-21·CVSS 7.8
CVE-2020-3898 [HIGH] CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c [fedora-all]
CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c
bugzilla·2020-04-14·CVSS 7.8
CVE-2020-3898 [HIGH] CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c
CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c
A heap-based buffer overflow was discovered in in libcups's ppdFindOption() function in ppd-mark.c:430. The issue can be reproduced by loading a crafted ppd file and calling the ppdMarkDefaults() libcups API function.
Discussion:
Acknowledgments:
Name: Apple Product Security
Upstream: Stephan Zeisberg (Security Research Labs)
---
Public:
https://support.apple.com/en-us/HT211100
---
Created cups tracking bugs for this issue:
Affects: fedora-all [bug 1826330]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4469 https://access.redhat.com/errata/RHSA-2020:4469
---
This bug is now closed. Further updates for individual products will be re
2020-10-22
Published