CVE-2020-3885: Medium severity tvos vulnerability
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.
Other sources
WebKit Page Loading. A logic issue was addressed with improved restrictions.
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3885
Impact: A file URL may be incorrectly processed. Description: A logic issue was addressed with improved restrictions.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3917
- CVE-2020-3883
- CVE-2020-9768
- CVE-2020-3919
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3918
- CVE-2020-9787
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3894
- CVE-2020-3899
- CVE-2020-3902
- CVE-2020-3901
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3897
- CVE-2020-3885
- CVE-2020-9784
- CVE-2020-9770
- CVE-2020-3913
- CVE-2020-3916
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3891
- CVE-2020-3890
- CVE-2020-9775
- CVE-2020-9781
- CVE-2020-3888
Frequently Asked Questions
What is CVE-2020-3885?
CVE-2020-3885 is a vulnerability related to WebKit Page Loading that addressed a logic issue with improved restrictions.
Which software versions are affected by CVE-2020-3885?
CVE-2020-3885 affects Safari version up to exclusive 13.1, iOS version up to exclusive 13.4, iPadOS version up to exclusive 13.4, iCloud for Windows version up to exclusive 10.9.3, iTunes for Windows version up to exclusive 12.10.5, iCloud for Windows version up to exclusive 7.18, and tvOS version up to exclusive 13.4.
What is the severity of CVE-2020-3885?
The severity of CVE-2020-3885 is not specified.
How can I fix CVE-2020-3885?
To fix CVE-2020-3885, update to the latest versions of affected software provided by Apple.
Where can I find more information about CVE-2020-3885?
You can find more information about CVE-2020-3885 on the Apple support website. (References: [1](https://support.apple.com/en-us/HT211104), [2](https://support.apple.com/en-us/HT211102), [3](https://support.apple.com/en-us/HT211101))