Type Confusion in Apple Safari - CVE-2020-3901

 

Type Confusion in Apple Safari - CVE-2020-3901

Published: March 27, 2020 / Updated: March 27, 2020


Vulnerability identifier: #VU26424
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-3901
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Apple Safari
Gentoo Linux
SUSE CaaS Platform
watchOS
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat CodeReady Linux Builder for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Apple iOS
iPadOS
SUSE Linux Enterprise High Performance Computing
Service Telemetry Framework
WebKitGTK+
WPE WebKit
webkit2gtk (Debian package)
gnome-remote-desktop (Red Hat package)
pipewire0.2 (Red Hat package)
pipewire (Red Hat package)
webrtc-audio-processing (Red Hat package)
dleyna-renderer (Red Hat package)
LibRaw (Red Hat package)
vte291 (Red Hat package)
PackageKit (Red Hat package)
xdg-desktop-portal-gtk (Red Hat package)
xdg-desktop-portal (Red Hat package)
frei0r-plugins (Red Hat package)
potrace (Red Hat package)
gtk-doc (Red Hat package)
gvfs (Red Hat package)
tracker (Red Hat package)
webkit2gtk3 (Red Hat package)
typelib-1_0-WebKit2WebExtension-4_0
libjavascriptcoregtk-4_0-18
libwebkit2gtk3-lang
libjavascriptcoregtk-4_0-18-debuginfo
libwebkit2gtk-4_0-37
libwebkit2gtk-4_0-37-debuginfo
typelib-1_0-JavaScriptCore-4_0
typelib-1_0-WebKit2-4_0
webkit2gtk-4_0-injected-bundles
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk3-debugsource
webkit2gtk3-devel
libsoup (Red Hat package)
gtk3 (Red Hat package)
gnome-photos (Red Hat package)
gnome-session (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
gnome-terminal (Red Hat package)
pygobject3 (Red Hat package)
gdm (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error when processing maliciously crafted web content. A remote attacker can trick a victim to open a specially crafted file or visit a malicious page, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2020-3901

Install updates from vendor's website.

Sources