Severity
7.8HIGHNVD
OSV5.5
EPSS
0.2%
top 62.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 24

Description

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5apple/macosunspecifiedmacOS Catalina 10.15.4
NVDapple/mac_os_x< 10.15.4
debiandebian/cups< cups 2.3.1-12 (bookworm)
Debianapple/cups< 2.3.1-12+3
Ubuntuapple/cups< 2.1.3-4ubuntu0.11+2

🔴Vulnerability Details

3
GHSA
GHSA-82r2-pfjv-q743: A memory corruption issue was addressed with improved validation2022-05-24
OSV
CVE-2020-3898: A memory corruption issue was addressed with improved validation2020-10-22
OSV
cups vulnerabilities2020-04-27

📋Vendor Advisories

3
Ubuntu
CUPS vulnerabilities2020-04-27
Red Hat
cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c2020-04-20
Debian
CVE-2020-3898: cups - A memory corruption issue was addressed with improved validation. This issue is ...2020

💬Community

3
Bugzilla
CVE-2020-4032 freerdp: integer casting vulnerability in update_recv_secondary_order2020-07-08
Bugzilla
CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c [fedora-all]2020-04-21
Bugzilla
CVE-2020-3898 cups: heap based buffer overflow in libcups's ppdFindOption() in ppd-mark.c2020-04-14