CVE-2020-3840: Buffer Overflow
IPSec. An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking.
Other sources
An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1. Loading a maliciously crafted racoon configuration file may lead to arbitrary code execution.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.3.1 - Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Fixed in 10.15.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.3.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.15.3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-3857
- CVE-2020-3855
- CVE-2020-3826
- CVE-2020-3870
- CVE-2020-3878
- CVE-2020-3880
- CVE-2020-3837
- CVE-2019-8836
- CVE-2020-3840
- CVE-2020-3875
- CVE-2020-3872
- CVE-2020-3836
- CVE-2020-3842
- CVE-2020-3853
- CVE-2020-3846
- CVE-2020-3856
- CVE-2020-3829
- CVE-2020-3825
- CVE-2020-3868
- CVE-2020-3862
- CVE-2020-3867
- CVE-2020-3865
- CVE-2020-3864
- CVE-2020-3838
- CVE-2020-3877
- CVE-2019-11043
- CVE-2020-3866
- CVE-2020-3848
- CVE-2020-3849
- CVE-2020-3850
- CVE-2020-3847
- CVE-2020-3835
- CVE-2020-3863
- CVE-2020-9774
- CVE-2020-3827
- CVE-2020-3845
- CVE-2020-3851
- CVE-2020-3871
- CVE-2020-3830
- CVE-2020-3854
- CVE-2019-18634
- CVE-2020-3839
- CVE-2020-3843
- CVE-2020-3869
- CVE-2020-3858
- CVE-2020-3831
- CVE-2020-3860
- CVE-2020-3873
- CVE-2020-3859
- CVE-2020-3844
- CVE-2020-3828
- CVE-2020-3841
- CVE-2020-3874
Frequently Asked Questions
What is CVE-2020-3840?
CVE-2020-3840 is an off by one issue in the handling of racoon configuration files in IPSec.
How does CVE-2020-3840 affect Apple devices?
CVE-2020-3840 affects Apple devices running tvOS, iOS, iPadOS, macOS Catalina, Mojave, and High Sierra.
How can I fix CVE-2020-3840?
To fix CVE-2020-3840, update your Apple device to the latest available version.
Where can I find more information about CVE-2020-3840?
You can find more information about CVE-2020-3840 in the references provided by Apple.