Buffer overflow in Apple Safari - CVE-2020-3899
Published: March 27, 2020 / Updated: March 27, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can trick a victim to open a specially crafted file or visit a malicious page, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
Gentoo Linux
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Apple iOS
iPadOS
Opensuse
Fedora
Service Telemetry Framework
WebKitGTK+
WPE WebKit
webkit2gtk (Debian package)
webkit2gtk (Ubuntu package)
gnome-remote-desktop (Red Hat package)
pipewire0.2 (Red Hat package)
pipewire (Red Hat package)
webrtc-audio-processing (Red Hat package)
dleyna-renderer (Red Hat package)
LibRaw (Red Hat package)
vte291 (Red Hat package)
PackageKit (Red Hat package)
xdg-desktop-portal-gtk (Red Hat package)
xdg-desktop-portal (Red Hat package)
frei0r-plugins (Red Hat package)
potrace (Red Hat package)
gtk-doc (Red Hat package)
gvfs (Red Hat package)
tracker (Red Hat package)
webkit2gtk3
webkit2gtk3 (Red Hat package)
libsoup (Red Hat package)
gtk3 (Red Hat package)
gnome-photos (Red Hat package)
gnome-session (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
gnome-terminal (Red Hat package)
pygobject3 (Red Hat package)
gdm (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2020-3899
WebKitGTK+ - update to 2.28.2
webkit2gtk (Debian package) - update to 2.28.2-2~deb10u1
WPE WebKit - update to 2.28.2
webkit2gtk (Ubuntu package) - addressed in versions 2.28.2-0ubuntu0.18.04.1, 2.28.2-0ubuntu0.19.10.1, 2.28.2-0ubuntu0.20.04.1
Quay - update to 3.3.3
Apple iOS - update to 13.4 17E255
iPadOS - update to 13.4
gnome-remote-desktop (Red Hat package) - update to 0.1.8-3.el8
pipewire0.2 (Red Hat package) - update to 0.2.7-6.el8
pipewire (Red Hat package) - update to 0.3.6-1.el8
webrtc-audio-processing (Red Hat package) - update to 0.3-9.el8
dleyna-renderer (Red Hat package) - update to 0.6.0-3.el8
LibRaw (Red Hat package) - update to 0.19.5-2.el8
vte291 (Red Hat package) - update to 0.52.4-2.el8
PackageKit (Red Hat package) - update to 1.1.12-6.el8
xdg-desktop-portal-gtk (Red Hat package) - update to 1.6.0-1.el8
xdg-desktop-portal (Red Hat package) - update to 1.6.0-2.el8
frei0r-plugins (Red Hat package) - update to 1.6.1-7.el8
potrace (Red Hat package) - update to 1.15-3.el8
gtk-doc (Red Hat package) - update to 1.28-2.el8
gvfs (Red Hat package) - update to 1.36.2-10.el8
tracker (Red Hat package) - update to 2.1.5-2.el8
webkit2gtk3 - addressed in versions 2.28.2-1.fc30, 2.28.2-1.fc31, 2.28.2-1.fc32
webkit2gtk3 (Red Hat package) - update to 2.28.4-1.el8
libsoup (Red Hat package) - update to 2.62.3-2.el8
gtk3 (Red Hat package) - update to 3.22.30-6.el8
gnome-photos (Red Hat package) - update to 3.28.1-3.el8
gnome-session (Red Hat package) - update to 3.28.1-10.el8
nautilus (Red Hat package) - update to 3.28.1-14.el8
gnome-control-center (Red Hat package) - update to 3.28.2-22.el8
gnome-terminal (Red Hat package) - update to 3.28.3-2.el8
pygobject3 (Red Hat package) - update to 3.28.3-2.el8
gdm (Red Hat package) - update to 3.28.3-34.el8
gsettings-desktop-schemas (Red Hat package) - update to 3.32.0-5.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-11.el8
gnome-shell-extensions (Red Hat package) - update to 3.32.1-11.el8
gnome-shell (Red Hat package) - update to 3.32.2-20.el8
mutter (Red Hat package) - update to 3.32.2-48.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple iOS and iPadOS
- Arch Linux update for webkit2gtk
- Ubuntu update for WebKitGTK
- Debian update for webkit2gtk
- OpenSUSE Linux update for webkit2gtk3
- Buffer overflow in WebKitGTK and WPE WebKit
- Gentoo update for WebKitGTK+
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Red Hat Enterprise Linux 8 update for GNOME
- Fedora 32 update for webkit2gtk3
- Fedora 30 update for webkit2gtk3
- Fedora 31 update for webkit2gtk3