CVE-2020-3838

The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.
References
Link Resource
http://seclists.org/fulldisclosure/2021/Apr/51 Third Party Advisory
https://support.apple.com/HT210918 Release Notes Vendor Advisory
https://support.apple.com/HT210919 Release Notes Vendor Advisory
https://support.apple.com/HT210920 Release Notes Vendor Advisory
https://support.apple.com/HT210921 Release Notes Vendor Advisory
https://support.apple.com/kb/HT212326 Vendor Advisory
https://support.apple.com/kb/HT212327 Vendor Advisory
http://seclists.org/fulldisclosure/2021/Apr/51 Third Party Advisory
https://support.apple.com/HT210918 Release Notes Vendor Advisory
https://support.apple.com/HT210919 Release Notes Vendor Advisory
https://support.apple.com/HT210920 Release Notes Vendor Advisory
https://support.apple.com/HT210921 Release Notes Vendor Advisory
https://support.apple.com/kb/HT212326 Vendor Advisory
https://support.apple.com/kb/HT212327 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-002:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-003:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-004:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-005:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-006:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-007:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2021-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2021-002:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:supplemental_update:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.14.6:supplemental_update_2:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:31

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2021/Apr/51 - Third Party Advisory () http://seclists.org/fulldisclosure/2021/Apr/51 - Third Party Advisory
References () https://support.apple.com/HT210918 - Release Notes, Vendor Advisory () https://support.apple.com/HT210918 - Release Notes, Vendor Advisory
References () https://support.apple.com/HT210919 - Release Notes, Vendor Advisory () https://support.apple.com/HT210919 - Release Notes, Vendor Advisory
References () https://support.apple.com/HT210920 - Release Notes, Vendor Advisory () https://support.apple.com/HT210920 - Release Notes, Vendor Advisory
References () https://support.apple.com/HT210921 - Release Notes, Vendor Advisory () https://support.apple.com/HT210921 - Release Notes, Vendor Advisory
References () https://support.apple.com/kb/HT212326 - Vendor Advisory () https://support.apple.com/kb/HT212326 - Vendor Advisory
References () https://support.apple.com/kb/HT212327 - Vendor Advisory () https://support.apple.com/kb/HT212327 - Vendor Advisory

Information

Published : 2020-02-27 21:15

Updated : 2024-11-21 05:31


NVD link : CVE-2020-3838

Mitre link : CVE-2020-3838

CVE.ORG link : CVE-2020-3838


JSON object : View

Products Affected

apple

  • mac_os_x
  • watchos
  • iphone_os
  • ipados
  • tvos
CWE
CWE-276

Incorrect Default Permissions