CVE-2020-3901
published 2020-04-01CVE-2020-3901: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.85%
76.8th percentile
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 10.9.3 | 10.9.3 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 10.9.3 | iCloud for Windows 10.9.3 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.18 | iCloud for Windows 7.18 |
| apple | ios | >= unspecified < iOS 13.4 and iPadOS 13.4 | iOS 13.4 and iPadOS 13.4 |
| apple | ipad_os | < 13.4 | 13.4 |
| apple | iphone_os | < 13.4 | 13.4 |
| apple | itunes | < 12.10.5 | 12.10.5 |
| apple | itunes_for_windows | >= unspecified < iTunes for Windows 12.10.5 | iTunes for Windows 12.10.5 |
| apple | safari | < 13.1 | 13.1 |
| apple | safari | >= unspecified < Safari 13.1 | Safari 13.1 |
| apple | tvos | < 13.4 | 13.4 |
| apple | tvos | >= unspecified < tvOS 13.4 | tvOS 13.4 |
| apple | watchos | < 6.2 | 6.2 |
| apple | watchos | >= unspecified < watchOS 6.2 | watchOS 6.2 |
| debian | webkit2gtk | < webkit2gtk 2.28.0-2 (bookworm) | webkit2gtk 2.28.0-2 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.28.0-2 (bookworm) | webkit2gtk 2.28.0-2 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rqcj-mh6f-fw77: A type confusion issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2020-3901 [MEDIUM] CWE-843 GHSA-rqcj-mh6f-fw77: A type confusion issue was addressed with improved memory handling
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.
OSV
CVE-2020-3901: A type confusion issue was addressed with improved memory handling
osv·2020-04-01·CVSS 8.8
CVE-2020-3901 [HIGH] CVE-2020-3901: A type confusion issue was addressed with improved memory handling
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.
Red Hat
webkitgtk: Type confusion leading to arbitrary code execution
vendor_redhat·2020-04-27·CVSS 8.8
CVE-2020-3901 [HIGH] webkitgtk: Type confusion leading to arbitrary code execution
webkitgtk: Type confusion leading to arbitrary code execution
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2020-3901: webkit2gtk - A type confusion issue was addressed with improved memory handling. This issue i...
vendor_debian·2020·CVSS 8.8
CVE-2020-3901 [HIGH] CVE-2020-3901: webkit2gtk - A type confusion issue was addressed with improved memory handling. This issue i...
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.28.0-2)
bullseye: resolved (fixed in 2.28.0-2)
forky: resolved (fixed in 2.28.0-2)
sid: resolved (fixed in 2.28.0-2)
trixie: resolved (fixed in 2.28.0-2)
No detection rules found.
No public exploits indexed.
https://support.apple.com/HT211101https://support.apple.com/HT211102https://support.apple.com/HT211103https://support.apple.com/HT211104https://support.apple.com/HT211105https://support.apple.com/HT211106https://support.apple.com/HT211107https://support.apple.com/HT211101https://support.apple.com/HT211102https://support.apple.com/HT211103https://support.apple.com/HT211104https://support.apple.com/HT211105https://support.apple.com/HT211106https://support.apple.com/HT211107
2020-04-01
Published