CVE-2020-27918
Summary
| CVE | CVE-2020-27918 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-08 22:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| About the security content of watchOS 7.1 - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| [SECURITY] Fedora 34 Update: webkit2gtk3-2.32.0-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| About the security content of iOS 14.2 and iPadOS 14.2 - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| Debian -- Security Information -- DSA-4877-1 webkit2gtk |
DEBIAN |
www.debian.org |
|
| Full Disclosure: APPLE-SA-2020-12-14-4 Additional information for APPLE-SA-2020-11-13-1 macOS Big Sur 11.0.1 |
FULLDISC |
seclists.org |
|
| WebkitGTK+: Multiple vulnerabilities (GLSA 202104-03) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| About the security content of macOS Big Sur 11.0.1 - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| [SECURITY] Fedora 33 Update: webkit2gtk3-2.32.0-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: webkit2gtk3-2.32.0-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| About the security content of tvOS 14.2 - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| About the security content of iCloud for Windows 11.5 - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| [SECURITY] Fedora 34 Update: webkit2gtk3-2.32.0-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: webkit2gtk3-2.30.6-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2021-0002 |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 32 Update: webkit2gtk3-2.30.6-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| About the security content of iTunes 12.11 for Windows - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| About the security content of Safari 14.0.1 - Apple Support |
MISC |
support.apple.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159499 Oracle Enterprise Linux Security Update for GNOME (ELSA-2021-4381)
- 174960 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2021:1430-1)
- 174986 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2021:1499-1)
- 178515 Debian Security Update for webkit2gtk (DSA 4877-1)
- 198312 Ubuntu Security Notification for Webkit2gtk Vulnerabilities (USN-4894-1)
- 239811 Red Hat Update for gnome security (RHSA-2021:4381)
- 281404 Fedora Security Update for webkit2gtk3 (FEDORA-2021-619711d709)
- 281405 Fedora Security Update for webkit2gtk3 (FEDORA-2021-864dc37032)
- 281406 Fedora Security Update for webkit2gtk3 (FEDORA-2021-8070916f7a)
- 296067 Oracle Solaris 11.4 Support Repository Update (SRU) 33.94.0 Missing (CPUAPR2021)
- 355438 Amazon Linux Security Advisory for webkitgtk4 : ALAS2-2023-2088
- 501711 Alpine Linux Security Update for webkit2gtk
- 501939 Alpine Linux Security Update for webkit2gtk
- 505518 Alpine Linux Security Update for webkit2gtk
- 710013 Gentoo Linux WebkitGTK+ Multiple Vulnerabilities (GLSA 202104-03)
- 750239 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2021:0637-1)
- 750655 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2021:1990-1)
- 751623 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0142-1)
- 751646 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0183-1)
- 751648 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0182-1)
- 751659 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-1)
- 751755 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-2)
- 940070 AlmaLinux Security Update for GNOME (ALSA-2021:4381)