CVE-2020-27918
Description
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
CWE
- (none)
Affected
- Apple / watchOS — v=unspecified <7.1 [affected]
- Apple / iOS and iPadOS — v=unspecified <14.2 [affected]
- Apple / tvOS — v=unspecified <14.2 [affected]
- Apple / macOS — v=unspecified <11.0 [affected]
- Apple / macOS — v=unspecified <12.11 [affected]
- Apple / macOS — v=unspecified <14.0 [affected]
- Apple / macOS — v=unspecified <11.5 [affected]
- Apple / macOS — v=unspecified <11.5 [affected]
CVSS
- (none)
References
- https://support.apple.com/en-us/HT211931 x_refsource_MISC
- https://support.apple.com/en-us/HT211935 x_refsource_MISC
- https://support.apple.com/en-us/HT211934 x_refsource_MISC
- https://support.apple.com/en-us/HT211928 x_refsource_MISC
- https://support.apple.com/en-us/HT211929 x_refsource_MISC
- https://support.apple.com/en-us/HT211930 x_refsource_MISC
- https://support.apple.com/en-us/HT211933 x_refsource_MISC
- http://seclists.org/fulldisclosure/2020/Dec/32 mailing-list, x_refsource_FULLDISC
- http://www.openwall.com/lists/oss-security/2021/03/22/1 mailing-list, x_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EQ3U3VBSOJB46WCO66TEWE5OAXLTU3YW/ vendor-advisory, x_refsource_FEDORA
- https://www.debian.org/security/2021/dsa-4877 vendor-advisory, x_refsource_DEBIAN
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3L6ZZOU5JS7E3RFYGLP7UFLXCG7TNLU/ vendor-advisory, x_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN6ZOD62CTO54CHTMJTHVEF6R2Y532TJ/ vendor-advisory, x_refsource_FEDORA
- https://security.gentoo.org/glsa/202104-03 vendor-advisory, x_refsource_GENTOO
Source
cvelistV5-main/cves/2020/27xxx/CVE-2020-27918.json