ZeroHour

CVE-2020-3840

CVSS 3.1
7.8 high
EPSS
1%p65
Published
()
Modified
Description

An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1. Loading a maliciously crafted racoon configuration file may lead to arbitrary code execution.

Vendors
apple
Products
ipados, iphone os, mac os x, tvos
Weakness
CWE-119, CWE-193
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.