CVE-2020-9806: High severity tvos vulnerability
Published May 18, 2020
·Updated
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
Other sources
A memory corruption issue was found in webkitgtk. Processing maliciously crafted web content may lead to arbitrary code execution. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
— Red Hat
WebKit. A memory corruption issue was addressed with improved state management.
Credit
Wen Xu(SSLab at Georgia Tech)
Affected Software
22 affected componentsFixes available
redhat/webkitgtk<2.28.3
2.28.3
ubuntu/webkit2gtk<2.28.3-0ubuntu0.18.04.1
2.28.3-0ubuntu0.18.04.1
ubuntu/webkit2gtk<2.28.3-0ubuntu0.19.10.1
2.28.3-0ubuntu0.19.10.1
ubuntu/webkit2gtk<2.28.3-0ubuntu0.20.04.1
2.28.3-0ubuntu0.20.04.1
debian/webkit2gtk
2.44.2-1~deb11u12.44.3-1~deb11u12.44.2-1~deb12u12.44.3-1~deb12u12.44.3-12.44.4-1
debian/wpewebkit
2.38.6-1~deb11u12.38.6-12.44.3-12.44.4-1
Apple tvOS<13.4.5
13.4.5
Apple WatchOS<6.2.5
6.2.5
Apple iCloud for Windows<11.2
11.2
Apple iCloud for Windows<7.19
7.19
Apple iTunes for Windows<12.10.7
12.10.7
Apple Safari<13.1.1
13.1.1
Apple iOS<13.5
13.5
Apple iPadOS<13.5
13.5
Apple Icloud Windows<7.19
Apple Icloud Windows>=11.0<11.2
Apple Itunes Windows<12.10.7
Apple Safari<13.1.1
Apple iPadOS<13.5
Apple iPhone OS<13.5
Apple tvOS<13.4.5
Apple WatchOS<6.2.5
Event History
Jun 9, 2020
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
DescriptionWeakness
Sep 16, 2020
Data Sourced
via Red Hat·02:19 PM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:53 PM
Description
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9827
- CVE-2020-9842
- CVE-2020-9815
- CVE-2020-9791
- CVE-2020-9829
- CVE-2020-9816
- CVE-2020-3878
- CVE-2020-9789
- CVE-2020-9790
- CVE-2020-9837
- CVE-2020-9821
- CVE-2020-9797
- CVE-2020-9852
- CVE-2020-9795
- CVE-2020-9808
- CVE-2020-9811
- CVE-2020-9812
- CVE-2020-9813
- CVE-2020-9814
- CVE-2020-9809
- CVE-2020-9994
- CVE-2014-9512
- CVE-2020-9854
- CVE-2020-9794
- CVE-2020-9839
- CVE-2020-9805
- CVE-2020-9802
- CVE-2020-9850
- CVE-2020-9843
- CVE-2020-9803
- CVE-2020-9806
- CVE-2020-9807
- CVE-2020-9800
- CVE-2019-20503
- CVE-2020-9819
- CVE-2020-9818
- CVE-2020-9801
- CVE-2020-9826
- CVE-2020-6616
- CVE-2020-9838
- CVE-2020-9835
- CVE-2020-9820
- CVE-2020-9823
- CVE-2020-9848
- CVE-2020-9825
- CVE-2020-9792
- CVE-2020-9844
- CVE-2020-9830