CVE-2020-3894

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
01/04/2020
Last modified:
02/06/2022

Description

A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* 10.9.3 (excluding)
cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* 12.10.5 (excluding)
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 13.1 (excluding)
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* 13.4 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 13.4 (excluding)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 13.4 (excluding)