CVE-2020-27918
Last modified
CVE-2020-27918 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. EPSS estimates a 1.36% chance of exploitation in the next 30 days.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Icloud | < 11.5 |
| Apple | Itunes | < 12.11 |
| Apple | Safari | < 14.0.1 |
| Apple | Ipados | < 14.2 |
| Apple | Iphone Os | < 14.2 |
| Apple | Macos | < 11.0.1 |
| Apple | Tvos | < 14.2 |
| Apple | Watchos | < 7.1 |
| Fedoraproject | Fedora | 32 |
| Fedoraproject | Fedora | 33 |
| Fedoraproject | Fedora | 34 |
| Debian | Debian Linux | 10.0 |
| Webkitgtk | Webkitgtk\+ | < 2.30.6 |
References
- http://seclists.org/fulldisclosure/2020/Dec/32Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/03/22/1Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202104-03Third Party Advisory
- https://support.apple.com/en-us/HT211928Vendor Advisory
- https://support.apple.com/en-us/HT211929Vendor Advisory
- https://support.apple.com/en-us/HT211930Vendor Advisory
- https://support.apple.com/en-us/HT211931Vendor Advisory
- https://support.apple.com/en-us/HT211933Vendor Advisory
- https://support.apple.com/en-us/HT211934Vendor Advisory
- https://support.apple.com/en-us/HT211935Vendor Advisory
- https://www.debian.org/security/2021/dsa-4877Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/32Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/03/22/1Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202104-03Third Party Advisory
- https://support.apple.com/en-us/HT211928Vendor Advisory
- https://support.apple.com/en-us/HT211929Vendor Advisory
- https://support.apple.com/en-us/HT211930Vendor Advisory
- https://support.apple.com/en-us/HT211931Vendor Advisory
- https://support.apple.com/en-us/HT211933Vendor Advisory
- https://support.apple.com/en-us/HT211934Vendor Advisory
- https://support.apple.com/en-us/HT211935Vendor Advisory
- https://www.debian.org/security/2021/dsa-4877Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27918?
How severe is CVE-2020-27918?
How do I fix CVE-2020-27918?
Are you affected by CVE-2020-27918?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
