CVE-2019-20503: Medium severity tvos vulnerability
Last updated 24 July 2024
Other sources
The inputs to sctploadaddressesfrominit are verified by sctparethereunrecognizedparameters; however, the two functions handled parameter bounds differently, resulting in out of bounds reads when parameters are partially outside a chunk.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-09/#CVE-2019-20503
— Red Hat
The inputs to sctploadaddressesfrominit are verified by sctparethereunrecognizedparameters; however, the two functions handled parameter bounds differently, resulting in out of bounds reads when parameters are partially outside a chunk.
— Mozilla
usrsctp before 2019-12-20 has out-of-bounds reads in sctploadaddressesfrominit.
— Launchpad
WebRTC. An access issue was addressed with improved memory management.
Credit
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9827
- CVE-2020-9842
- CVE-2020-9815
- CVE-2020-9791
- CVE-2020-9829
- CVE-2020-9816
- CVE-2020-3878
- CVE-2020-9789
- CVE-2020-9790
- CVE-2020-9837
- CVE-2020-9821
- CVE-2020-9797
- CVE-2020-9852
- CVE-2020-9795
- CVE-2020-9808
- CVE-2020-9811
- CVE-2020-9812
- CVE-2020-9813
- CVE-2020-9814
- CVE-2020-9809
- CVE-2020-9994
- CVE-2014-9512
- CVE-2020-9854
- CVE-2020-9794
- CVE-2020-9839
- CVE-2020-9805
- CVE-2020-9802
- CVE-2020-9850
- CVE-2020-9843
- CVE-2020-9803
- CVE-2020-9806
- CVE-2020-9807
- CVE-2020-9800
- CVE-2019-20503
- CVE-2020-9819
- CVE-2020-9818
- CVE-2020-6805
- CVE-2020-6806
- CVE-2020-6807
- CVE-2020-6811
- CVE-2020-6812
- CVE-2020-6814
- CVE-2020-6808
- CVE-2020-6809
- CVE-2020-6810
- CVE-2020-6813
- CVE-2020-6815
- CVE-2020-9801
- CVE-2020-9826
- CVE-2020-6616
- CVE-2020-9838
- CVE-2020-9835
- CVE-2020-9820
- CVE-2020-9823
- CVE-2020-9848
- CVE-2020-9825
- CVE-2020-9792
- CVE-2020-9844
- CVE-2020-9830
Frequently Asked Questions
What is CVE-2019-20503?
CVE-2019-20503 is a vulnerability in WebRTC that allows for out of bounds reads when parameters are partially outside a chunk.
How does CVE-2019-20503 impact Mozilla Firefox?
CVE-2019-20503 affects Mozilla Firefox version up to 74 and Firefox ESR version up to 68.6, potentially allowing for out of bounds reads.
How does CVE-2019-20503 impact Apple Safari, iOS, iPadOS, watchOS, and tvOS?
CVE-2019-20503 impacts Apple Safari, iOS, iPadOS, watchOS, and tvOS versions up to 13.1.1, 13.5, 13.5, 6.2.5, and 13.4.5 respectively, potentially allowing for out of bounds reads.
What is the severity of CVE-2019-20503?
CVE-2019-20503 is classified as a medium severity vulnerability with a severity score of 4 out of 10.
How can I fix CVE-2019-20503?
To fix CVE-2019-20503, update to the latest version of the affected software, such as Mozilla Firefox 74 or Apple Safari 13.1.1.