CVE Vulnerabilities

CVE-2020-3885

Always-Incorrect Control Flow Implementation

Published: Apr 01, 2020 | Modified: May 31, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.

Weakness

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

Affected Software

Name Vendor Start Version End Version
Icloud Apple * 7.18 (excluding)
Icloud Apple 10.0.0 (including) 10.9.3 (excluding)
Itunes Apple * 12.10.5 (excluding)
Safari Apple * 13.1 (excluding)
Ipad_os Apple * 13.4 (excluding)
Iphone_os Apple * 13.4 (excluding)
Tvos Apple * 13.4 (excluding)

References