CVE-2020-3894: Race Condition
A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
Other sources
WebKit. A race condition was addressed with additional validation.
WebKitGTK Security Advisory WSA-2020-0005 describes the following issue:
CVE-2020-3894
Impact: An application may be able to read restricted memory. Description: A race condition was addressed with additional validation.
Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0.
— Red Hat
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/webkitgtkto a version that resolves this vulnerability.Fixed in 2.28.0 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 10.9.3 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 7.18 - Upgrade
Upgrade
iTunesto a version that resolves this vulnerability.Fixed in 12.10.5 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 13.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
WebKitGTKto a version that resolves this vulnerability.Fixed in 2.28.0Patch WSA-2020-0005 - Upgrade
Upgrade
WPE WebKitto a version that resolves this vulnerability.Fixed in 2.28.0Patch WSA-2020-0005 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 13.4Patch WSA-2020-0005 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 13.4Patch WSA-2020-0005 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.4Patch WSA-2020-0005 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 13.1Patch WSA-2020-0005 - Upgrade
Upgrade
iTunes for Windowsto a version that resolves this vulnerability.Fixed in 12.10.5Patch WSA-2020-0005 - Upgrade
Upgrade
iCloud for Windowsto a version that resolves this vulnerability.Fixed in 10.9.3Patch WSA-2020-0005 - Upgrade
Upgrade
iCloud for Windowsto a version that resolves this vulnerability.Fixed in 7.18Patch WSA-2020-0005
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3917
- CVE-2020-3883
- CVE-2020-9768
- CVE-2020-3919
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3918
- CVE-2020-9787
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3894
- CVE-2020-3899
- CVE-2020-3902
- CVE-2020-3901
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3897
- CVE-2020-3885
- CVE-2020-9784
- CVE-2020-9770
- CVE-2020-3913
- CVE-2020-3916
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3891
- CVE-2020-3890
- CVE-2020-9775
- CVE-2020-9781
- CVE-2020-3888
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-3894.
What is the title of the vulnerability?
The title of the vulnerability is WebKit. A race condition was addressed with additional validation.
Which software products are affected by this vulnerability?
The software products affected by this vulnerability are Apple Safari, Apple iOS, Apple iPadOS, Apple iTunes for Windows, Apple iCloud for Windows, and Apple tvOS.
What is the severity of CVE-2020-3894?
The severity of CVE-2020-3894 is not specified in the provided information.
Are there any known remedies for this vulnerability?
Yes, there are known remedies for this vulnerability. Please refer to the provided references for more information.