CVE-2020-9948: High severity ibm cloud pak for security vulnerability
A flaw was found in WebKitGTK. A type confusion issue was addressed with improved memory handling. Processing maliciously crafted web content may lead to arbitrary code execution.
Reference: https://webkitgtk.org/security/WSA-2020-0008.html
Other sources
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
— Launchpad
Apple Safari could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion in the WebKit component. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
WebKit. A type confusion issue was addressed with improved memory handling.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-9948.
What software is affected by this vulnerability?
The Safari web browser version up to but excluding 14.0 is affected by this vulnerability.
What is the severity level of CVE-2020-9948?
The severity level of CVE-2020-9948 has not been provided.
How can I fix this vulnerability?
To fix this vulnerability, update your Safari web browser to version 14.0 or newer.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Apple support website at the following link: [https://support.apple.com/en-us/HT211845](https://support.apple.com/en-us/HT211845).