var-202011-0444
Vulnerability from variot
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Google Chrome Is vulnerable to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Google Chrome is a web browser developed by Google (Google). Chrome has security holes. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256
APPLE-SA-2020-12-14-3 macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave
macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave addresses the following issues. Information about the security content is also available at https://support.apple.com/HT212011.
AMD Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A malicious application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved input validation. CVE-2020-27914: Yu Wang of Didi Research America CVE-2020-27915: Yu Wang of Didi Research America
App Store Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An application may be able to gain elevated privileges Description: This issue was addressed by removing the vulnerable code. CVE-2020-27903: Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab
AppleGraphicsControl Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A validation issue was addressed with improved logic. CVE-2020-27941: shrek_wzw
AppleMobileFileIntegrity Available for: macOS Big Sur 11.0.1 Impact: A malicious application may be able to bypass Privacy preferences Description: This issue was addressed with improved checks. CVE-2020-29621: Wojciech Reguła (@_r3ggi) of SecuRing
Audio Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation. CVE-2020-27910: JunDong Xie and XingWei Lin of Ant Security Light- Year Lab
Audio Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A malicious application may be able to read restricted memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2020-9943: JunDong Xie of Ant Security Light-Year Lab
Audio Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An application may be able to read restricted memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2020-9944: JunDong Xie of Ant Security Light-Year Lab
Audio Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution Description: An out-of-bounds write was addressed with improved input validation. CVE-2020-27916: JunDong Xie of Ant Security Light-Year Lab
Bluetooth Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A remote attacker may be able to cause unexpected application termination or heap corruption Description: Multiple integer overflows were addressed with improved input validation. CVE-2020-27906: Zuozhi Fan (@pattern_F_) of Ant Group Tianqiong Security Lab
CoreAudio Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2020-27948: JunDong Xie of Ant Security Light-Year Lab
CoreAudio Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation. CVE-2020-9960: JunDong Xie and XingWei Lin of Ant Security Light-Year Lab CVE-2020-27908: JunDong Xie and XingWei Lin of Ant Security Light- Year Lab
CoreAudio Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution Description: An out-of-bounds write was addressed with improved input validation. CVE-2020-10017: Francis working with Trend Micro Zero Day Initiative, JunDong Xie of Ant Security Light-Year Lab
CoreText Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: A logic issue was addressed with improved state management. CVE-2020-27922: Mickey Jin of Trend Micro
FontParser Available for: macOS Big Sur 11.0.1 Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An information disclosure issue was addressed with improved state management. CVE-2020-27946: Mateusz Jurczyk of Google Project Zero
FontParser Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: A buffer overflow was addressed with improved size validation. CVE-2020-9962: Yiğit Can YILMAZ (@yilmazcanyigit)
FontParser Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: An out-of-bounds write was addressed with improved input validation. CVE-2020-27952: an anonymous researcher, Mickey Jin and Junzhi Lu of Trend Micro
FontParser Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation. CVE-2020-9956: Mickey Jin and Junzhi Lu of Trend Micro Mobile Security Research Team working with Trend Micro’s Zero Day Initiative
FontParser Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. CVE-2020-27931: Apple CVE-2020-27943: Mateusz Jurczyk of Google Project Zero CVE-2020-27944: Mateusz Jurczyk of Google Project Zero
Foundation Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A local user may be able to read arbitrary files Description: A logic issue was addressed with improved state management. CVE-2020-10002: James Hutchins
Graphics Drivers Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved input validation. CVE-2020-27947: ABC Research s.r.o. working with Trend Micro Zero Day Initiative
Graphics Drivers Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: A malicious application may be able to execute arbitrary code with system privileges Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2020-29612: ABC Research s.r.o. working with Trend Micro Zero Day Initiative
HomeKit Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An attacker in a privileged network position may be able to unexpectedly alter application state Description: This issue was addressed with improved setting propagation. CVE-2020-9978: Luyi Xing, Dongfang Zhao, and Xiaofeng Wang of Indiana University Bloomington, Yan Jia of Xidian University and University of Chinese Academy of Sciences, and Bin Yuan of HuaZhong University of Science and Technology
Image Processing Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: An out-of-bounds write was addressed with improved input validation. CVE-2020-27919: Hou JingYi (@hjy79425575) of Qihoo 360 CERT, Xingwei Lin of Ant Security Light-Year Lab
ImageIO Available for: macOS Big Sur 11.0.1 Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved input validation. CVE-2020-29616: zhouat working with Trend Micro Zero Day Initiative
ImageIO Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation. CVE-2020-27924: Lei Sun CVE-2020-29618: XingWei Lin of Ant Security Light-Year Lab
ImageIO Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2020-29611: Ivan Fratric of Google Project Zero
ImageIO Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: Processing a maliciously crafted image may lead to heap corruption Description: An out-of-bounds read was addressed with improved input validation. CVE-2020-29617: XingWei Lin of Ant Security Light-Year Lab CVE-2020-29619: XingWei Lin of Ant Security Light-Year Lab
ImageIO Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted image may lead to arbitrary code execution Description: An out-of-bounds write was addressed with improved input validation. CVE-2020-27912: Xingwei Lin of Ant Security Light-Year Lab CVE-2020-27923: Lei Sun
Intel Graphics Driver Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An application may be able to execute arbitrary code with kernel privileges Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2020-10015: ABC Research s.r.o. working with Trend Micro Zero Day Initiative CVE-2020-27897: Xiaolong Bai and Min (Spark) Zheng of Alibaba Inc. and Luyi Xing of Indiana University Bloomington
Intel Graphics Driver Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2020-27907: ABC Research s.r.o. working with Trend Micro Zero Day Initiative
Kernel Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A malicious application may be able to determine kernel memory layout Description: A logic issue was addressed with improved state management. CVE-2020-9974: Tommy Muir (@Muirey03)
Kernel Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved state management. CVE-2020-10016: Alex Helie
Kernel Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory Description: Multiple memory corruption issues were addressed with improved input validation. CVE-2020-9967: Alex Plaskett (@alexjplaskett)
Kernel Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A use after free issue was addressed with improved memory management. CVE-2020-9975: Tielei Wang of Pangu Lab
Kernel Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A race condition was addressed with improved state handling. CVE-2020-27921: Linus Henze (pinauten.de)
Kernel Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS Big Sur 11.0.1 Impact: A malicious application may cause unexpected changes in memory belonging to processes traced by DTrace Description: This issue was addressed with improved checks to prevent unauthorized actions. CVE-2020-27949: Steffen Klee (@_kleest) of TU Darmstadt, Secure Mobile Networking Lab
Kernel Available for: macOS Big Sur 11.0.1 Impact: A malicious application may be able to elevate privileges Description: This issue was addressed with improved entitlements. CVE-2020-29620: Csaba Fitzl (@theevilbit) of Offensive Security
libxml2 Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution Description: An integer overflow was addressed through improved input validation. CVE-2020-27911: found by OSS-Fuzz
libxml2 Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing maliciously crafted web content may lead to code execution Description: A use after free issue was addressed with improved memory management. CVE-2020-27920: found by OSS-Fuzz
libxml2 Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management. CVE-2020-27926: found by OSS-Fuzz
libxpc Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A malicious application may be able to break out of its sandbox Description: A parsing issue in the handling of directory paths was addressed with improved path validation. CVE-2020-10014: Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab
Logging Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A local attacker may be able to elevate their privileges Description: A path handling issue was addressed with improved validation. CVE-2020-10010: Tommy Muir (@Muirey03)
Model I/O Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation. CVE-2020-13524: Aleksandar Nikolic of Cisco Talos
Model I/O Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution Description: A logic issue was addressed with improved state management. CVE-2020-10004: Aleksandar Nikolic of Cisco Talos
NSRemoteView Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: A logic issue was addressed with improved restrictions. CVE-2020-27901: Thijs Alkemade of Computest Research Division
Power Management Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A malicious application may be able to determine kernel memory layout Description: A logic issue was addressed with improved state management. CVE-2020-10007: singi@theori working with Trend Micro Zero Day Initiative
Quick Look Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: Processing a maliciously crafted document may lead to a cross site scripting attack Description: An access issue was addressed with improved access restrictions. CVE-2020-10012: Heige of KnownSec 404 Team (knownsec.com) and Bo Qu of Palo Alto Networks (paloaltonetworks.com)
Ruby Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A remote attacker may be able to modify the file system Description: A path handling issue was addressed with improved validation. CVE-2020-27896: an anonymous researcher
System Preferences Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: A logic issue was addressed with improved state management. CVE-2020-10009: Thijs Alkemade of Computest Research Division
WebRTC Available for: macOS Big Sur 11.0.1 Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management. CVE-2020-15969: an anonymous researcher
Wi-Fi Available for: macOS Mojave 10.14.6, macOS Catalina 10.15.7 Impact: An attacker may be able to bypass Managed Frame Protection Description: A denial of service issue was addressed with improved state handling. CVE-2020-27898: Stephan Marais of University of Johannesburg
Installation note:
macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/
Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222
This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAl/YBj8ACgkQZcsbuWJ6 jjCVjw//QGrhMvU+nyuS1UwWs7rcqDJDNh0Zb7yUJali2Bdc9/l++i2pLFbmAwes 7AYCag+T3h3aP7YJAN13zb8KBmUcmnWkWupfx8kEGqHxSXnQTXvaEI59RyCobOCj OVPtboPMH1d94+6dABMp9kiLAHoZezm3hdF8ShT2Hqgq2TB16wZsa/EvhJVSaduA 7RttG6EHBTin6UU3M/+vcfJWqkg4O0YuZpQaconDa5Pd81jpUMeduzfRvS5i+PVS cehtHPWjCN15+sQ29q11yhP3v+sYh0DJEl2LWaBnDo2TlC1gHx70H5ZsAFLHChcd rXkl1tm6GV3UWVhFq0jQc1DP+IwbuL6jHI/wIjYx7itk9XECppyhhiuImOaLiIUH CBgAjwVHY1GUdTH97iPEQFF61v3sjpRLleLMZW7+9ZTt4pEDwMVHk9vKgVK5BUa6 lrKWtBHL3AtaXtxC9y8XGe3IYEBLAszHMUJfF1BR+D/niDRlztvoj72/3PPwtk2t tuUE9RGzpSXCQ1CX6vW7zS2ddVmQfJqcPX721k4OVpFNlMXkjZkm2Q/xwr5qq99v Up9BA+ITksthGYfGAY5bBV1LsjK1NtdNHQGpZe4l9bu4ONgUvmL8iBb/LnS6wKB1 HGcdHEmXvbx+Akl/fvTdG8RSvyoYuFJHkuYv0DMWiri8yN1q+C4= =osnP -----END PGP SIGNATURE-----
. 8.1) - aarch64, ppc64le, s390x, x86_64
-
8) - aarch64, ppc64le, x86_64
-
Summary:
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary.
Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
- Relevant releases/architectures:
Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, i686, x86_64 Red Hat Enterprise Linux HPC Node Supplementary (v. 6) - i686, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, i686, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, i686, x86_64
- Description:
Chromium is an open-source web browser, powered by WebKit (Blink).
This update upgrades Chromium to version 86.0.4240.75.
Security Fix(es):
-
chromium-browser: Use after free in payments (CVE-2020-15967)
-
chromium-browser: Use after free in Blink (CVE-2020-15968)
-
chromium-browser: Use after free in WebRTC (CVE-2020-15969)
-
chromium-browser: Use after free in NFC (CVE-2020-15970)
-
chromium-browser: Use after free in printing (CVE-2020-15971)
-
chromium-browser: Use after free in audio (CVE-2020-15972)
-
chromium-browser: Use after free in autofill (CVE-2020-15990)
-
chromium-browser: Use after free in password manager (CVE-2020-15991)
-
chromium-browser: Inappropriate implementation in networking (CVE-2020-6557)
-
chromium-browser: Insufficient policy enforcement in extensions (CVE-2020-15973)
-
chromium-browser: Integer overflow in Blink (CVE-2020-15974)
-
chromium-browser: Integer overflow in SwiftShader (CVE-2020-15975)
-
chromium-browser: Use after free in WebXR (CVE-2020-15976)
-
chromium-browser: Insufficient data validation in dialogs (CVE-2020-15977)
-
chromium-browser: Insufficient data validation in navigation (CVE-2020-15978)
-
chromium-browser: Inappropriate implementation in V8 (CVE-2020-15979)
-
chromium-browser: Insufficient policy enforcement in Intents (CVE-2020-15980)
-
chromium-browser: Out of bounds read in audio (CVE-2020-15981)
-
chromium-browser: Side-channel information leakage in cache (CVE-2020-15982)
-
chromium-browser: Insufficient data validation in webUI (CVE-2020-15983)
-
chromium-browser: Insufficient policy enforcement in Omnibox (CVE-2020-15984)
-
chromium-browser: Inappropriate implementation in Blink (CVE-2020-15985)
-
chromium-browser: Integer overflow in media (CVE-2020-15986)
-
chromium-browser: Use after free in WebRTC (CVE-2020-15987)
-
chromium-browser: Insufficient policy enforcement in networking (CVE-2020-15992)
-
chromium-browser: Insufficient policy enforcement in downloads (CVE-2020-15988)
-
chromium-browser: Uninitialized use in PDFium (CVE-2020-15989)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
- Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, Chromium must be restarted for the changes to take effect.
- Bugs fixed (https://bugzilla.redhat.com/):
1885883 - CVE-2020-15967 chromium-browser: Use after free in payments 1885884 - CVE-2020-15968 chromium-browser: Use after free in Blink 1885885 - CVE-2020-15969 chromium-browser: Use after free in WebRTC 1885886 - CVE-2020-15970 chromium-browser: Use after free in NFC 1885887 - CVE-2020-15971 chromium-browser: Use after free in printing 1885888 - CVE-2020-15972 chromium-browser: Use after free in audio 1885889 - CVE-2020-15990 chromium-browser: Use after free in autofill 1885890 - CVE-2020-15991 chromium-browser: Use after free in password manager 1885891 - CVE-2020-15973 chromium-browser: Insufficient policy enforcement in extensions 1885892 - CVE-2020-15974 chromium-browser: Integer overflow in Blink 1885893 - CVE-2020-15975 chromium-browser: Integer overflow in SwiftShader 1885894 - CVE-2020-15976 chromium-browser: Use after free in WebXR 1885896 - CVE-2020-6557 chromium-browser: Inappropriate implementation in networking 1885897 - CVE-2020-15977 chromium-browser: Insufficient data validation in dialogs 1885899 - CVE-2020-15978 chromium-browser: Insufficient data validation in navigation 1885901 - CVE-2020-15979 chromium-browser: Inappropriate implementation in V8 1885902 - CVE-2020-15980 chromium-browser: Insufficient policy enforcement in Intents 1885903 - CVE-2020-15981 chromium-browser: Out of bounds read in audio 1885904 - CVE-2020-15982 chromium-browser: Side-channel information leakage in cache 1885905 - CVE-2020-15983 chromium-browser: Insufficient data validation in webUI 1885906 - CVE-2020-15984 chromium-browser: Insufficient policy enforcement in Omnibox 1885907 - CVE-2020-15985 chromium-browser: Inappropriate implementation in Blink 1885908 - CVE-2020-15986 chromium-browser: Integer overflow in media 1885909 - CVE-2020-15987 chromium-browser: Use after free in WebRTC 1885910 - CVE-2020-15992 chromium-browser: Insufficient policy enforcement in networking 1885911 - CVE-2020-15988 chromium-browser: Insufficient policy enforcement in downloads 1885912 - CVE-2020-15989 chromium-browser: Uninitialized use in PDFium
- Package List:
Red Hat Enterprise Linux Desktop Supplementary (v. 6):
i386: chromium-browser-86.0.4240.75-1.el6_10.i686.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm
i686: chromium-browser-86.0.4240.75-1.el6_10.i686.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm
x86_64: chromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm
Red Hat Enterprise Linux HPC Node Supplementary (v. 6):
i686: chromium-browser-86.0.4240.75-1.el6_10.i686.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm
x86_64: chromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm
Red Hat Enterprise Linux Server Supplementary (v. 6):
i386: chromium-browser-86.0.4240.75-1.el6_10.i686.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm
i686: chromium-browser-86.0.4240.75-1.el6_10.i686.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm
x86_64: chromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm
Red Hat Enterprise Linux Workstation Supplementary (v. 6):
i386: chromium-browser-86.0.4240.75-1.el6_10.i686.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm
i686: chromium-browser-86.0.4240.75-1.el6_10.i686.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm
x86_64: chromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm chromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/
- References:
https://access.redhat.com/security/cve/CVE-2020-6557 https://access.redhat.com/security/cve/CVE-2020-15967 https://access.redhat.com/security/cve/CVE-2020-15968 https://access.redhat.com/security/cve/CVE-2020-15969 https://access.redhat.com/security/cve/CVE-2020-15970 https://access.redhat.com/security/cve/CVE-2020-15971 https://access.redhat.com/security/cve/CVE-2020-15972 https://access.redhat.com/security/cve/CVE-2020-15973 https://access.redhat.com/security/cve/CVE-2020-15974 https://access.redhat.com/security/cve/CVE-2020-15975 https://access.redhat.com/security/cve/CVE-2020-15976 https://access.redhat.com/security/cve/CVE-2020-15977 https://access.redhat.com/security/cve/CVE-2020-15978 https://access.redhat.com/security/cve/CVE-2020-15979 https://access.redhat.com/security/cve/CVE-2020-15980 https://access.redhat.com/security/cve/CVE-2020-15981 https://access.redhat.com/security/cve/CVE-2020-15982 https://access.redhat.com/security/cve/CVE-2020-15983 https://access.redhat.com/security/cve/CVE-2020-15984 https://access.redhat.com/security/cve/CVE-2020-15985 https://access.redhat.com/security/cve/CVE-2020-15986 https://access.redhat.com/security/cve/CVE-2020-15987 https://access.redhat.com/security/cve/CVE-2020-15988 https://access.redhat.com/security/cve/CVE-2020-15989 https://access.redhat.com/security/cve/CVE-2020-15990 https://access.redhat.com/security/cve/CVE-2020-15991 https://access.redhat.com/security/cve/CVE-2020-15992 https://access.redhat.com/security/updates/classification/#critical
- Contact:
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/
Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIVAwUBX4VjutzjgjWX9erEAQiBog/8D4EAnQmD6yqmkt9gVgCzoz1v/uOgnTHv lghXbEidNiTmb8DlvwZKbqA/2wz/kz+vW5v0bXZNjngYnbZsev252qT9L2LQ99UA +uirPF/zddn+T0tZ5PQHWBYpWgjF8XRQu7lJo7QHbB7GEMXJJ4SBN3erYqOjKKUo 3DakSX4DH1VIrSY+6kJ6fx26IwD7tWSBlsRklatxX1NkhrBg0Ha7lWjHhRV6WLjz CZFxwFNJJ6bGsf8eIaaps8Ab21m87BbwOyGt2aaFT9sC5noR4mTTjBGB4lmbslB3 Vcl7PSxqs/AzDK6fAqLOJ7nqZJpiQq9ii5Z3oBbiG3J8BO6sgY7cG+D2bVWD+3eV 9L13REiW/iPXqGbpgPre8WhAwg3wdNYDiaYO6pIC7N1a/btxIdq5Gjb31dWiFdyq XOtdEO9CieZGYNEoKf+wfe03SXCEvJz0EZZVwcFhqd8cF8xhUa2MNjpKDHryUjXg 8rJGA+5uS/UJHwToK++Q4+0Ze/jIxSuKRA7h9UhdACksgeMmFUdyfuLVfx1RdgEX TRtO8kHaGBHz60SY4Kd6xkZks1+FqotFF2zvs4gq8XvPFbHvPgt36qbtxOHYj1BF pl+WqaRsDOp6VmbMLAEJwZnRsR0dNN62MCgxB5sNRb5l7sSYOqYClV2zR47cEgFJ ObQiF6iTAHk=AItV -----END PGP SIGNATURE-----
-- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . 7) - x86_64
- Description:
Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
-
Mozilla: Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4 (CVE-2020-15683)
-
chromium-browser: Use after free in WebRTC (CVE-2020-15969)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bugs fixed (https://bugzilla.redhat.com/):
1885885 - CVE-2020-15969 chromium-browser: Use after free in WebRTC 1889932 - CVE-2020-15683 Mozilla: Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4
For the stable distribution (buster), these problems have been fixed in version 78.4.0esr-1~deb10u2.
We recommend that you upgrade your firefox-esr packages
Show details on source website{ "@context": { "@vocab": "https://www.variotdbs.pl/ref/VARIoTentry#", "affected_products": { "@id": "https://www.variotdbs.pl/ref/affected_products" }, "configurations": { "@id": "https://www.variotdbs.pl/ref/configurations" }, "credits": { "@id": "https://www.variotdbs.pl/ref/credits" }, "cvss": { "@id": "https://www.variotdbs.pl/ref/cvss/" }, "description": { "@id": "https://www.variotdbs.pl/ref/description/" }, "exploit_availability": { "@id": "https://www.variotdbs.pl/ref/exploit_availability/" }, "external_ids": { "@id": "https://www.variotdbs.pl/ref/external_ids/" }, "iot": { "@id": "https://www.variotdbs.pl/ref/iot/" }, "iot_taxonomy": { "@id": "https://www.variotdbs.pl/ref/iot_taxonomy/" }, "patch": { "@id": "https://www.variotdbs.pl/ref/patch/" }, "problemtype_data": { "@id": "https://www.variotdbs.pl/ref/problemtype_data/" }, "references": { "@id": "https://www.variotdbs.pl/ref/references/" }, "sources": { "@id": "https://www.variotdbs.pl/ref/sources/" }, "sources_release_date": { "@id": "https://www.variotdbs.pl/ref/sources_release_date/" }, "sources_update_date": { "@id": "https://www.variotdbs.pl/ref/sources_update_date/" }, "threat_type": { "@id": "https://www.variotdbs.pl/ref/threat_type/" }, "title": { "@id": "https://www.variotdbs.pl/ref/title/" }, "type": { "@id": "https://www.variotdbs.pl/ref/type/" } }, "@id": "https://www.variotdbs.pl/vuln/VAR-202011-0444", "affected_products": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/affected_products#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" }, "@id": "https://www.variotdbs.pl/ref/sources" } }, "data": [ { "model": "fedora", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "32" }, { "model": "chrome", "scope": "lt", "trust": 1.0, "vendor": "google", "version": "86.0.4240.75" }, { "model": "tvos", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "14.3" }, { "model": "fedora", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "31" }, { "model": "safari", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "14.0.2" }, { "model": "backports sle", "scope": "eq", "trust": 1.0, "vendor": "opensuse", "version": "15.0" }, { "model": "iphone os", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "14.3" }, { "model": "linux", "scope": "eq", "trust": 1.0, "vendor": "debian", "version": "10.0" }, { "model": "macos", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "11.1" }, { "model": "ipados", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "14.3" }, { "model": "watchos", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "7.2" }, { "model": "fedora", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "33" }, { "model": "watchos", "scope": null, "trust": 0.8, "vendor": "\u30a2\u30c3\u30d7\u30eb", "version": null }, { "model": "ios", "scope": null, "trust": 0.8, "vendor": "\u30a2\u30c3\u30d7\u30eb", "version": null }, { "model": "ipados", "scope": null, "trust": 0.8, "vendor": "\u30a2\u30c3\u30d7\u30eb", "version": null }, { "model": "backports sle", "scope": null, "trust": 0.8, "vendor": "opensuse", "version": null }, { "model": "macos big sur", "scope": null, "trust": 0.8, "vendor": "\u30a2\u30c3\u30d7\u30eb", "version": null }, { "model": "gnu/linux", "scope": null, "trust": 0.8, "vendor": "debian", "version": null }, { "model": "fedora", "scope": null, "trust": 0.8, "vendor": "fedora", "version": null }, { "model": "safari", "scope": null, "trust": 0.8, "vendor": "\u30a2\u30c3\u30d7\u30eb", "version": null }, { "model": "tvos", "scope": null, "trust": 0.8, "vendor": "\u30a2\u30c3\u30d7\u30eb", "version": null }, { "model": "chrome", "scope": null, "trust": 0.8, "vendor": "google", "version": null } ], "sources": [ { "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "db": "NVD", "id": "CVE-2020-15969" } ] }, "credits": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/credits#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "Red Hat", "sources": [ { "db": "PACKETSTORM", "id": "159686" }, { "db": "PACKETSTORM", "id": "159683" }, { "db": "PACKETSTORM", "id": "159888" }, { "db": "PACKETSTORM", "id": "159536" }, { "db": "PACKETSTORM", "id": "159893" } ], "trust": 0.5 }, "cve": "CVE-2020-15969", "cvss": { "@context": { "cvssV2": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/cvss/cvssV2#" }, "@id": "https://www.variotdbs.pl/ref/cvss/cvssV2" }, "cvssV3": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/cvss/cvssV3#" }, "@id": "https://www.variotdbs.pl/ref/cvss/cvssV3/" }, "severity": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/cvss/severity#" }, "@id": "https://www.variotdbs.pl/ref/cvss/severity" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" }, "@id": "https://www.variotdbs.pl/ref/sources" } }, "data": [ { "cvssV2": [ { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "author": "nvd@nist.gov", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "exploitabilityScore": 8.6, "id": "CVE-2020-15969", "impactScore": 6.4, "integrityImpact": "PARTIAL", "severity": "MEDIUM", "trust": 1.8, "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "author": "VULHUB", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "exploitabilityScore": 8.6, "id": "VHN-169000", "impactScore": 6.4, "integrityImpact": "PARTIAL", "severity": "MEDIUM", "trust": 0.1, "vectorString": "AV:N/AC:M/AU:N/C:P/I:P/A:P", "version": "2.0" } ], "cvssV3": [ { "attackComplexity": "LOW", "attackVector": "NETWORK", "author": "nvd@nist.gov", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "exploitabilityScore": 2.8, "id": "CVE-2020-15969", "impactScore": 5.9, "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "trust": 1.0, "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, { "attackComplexity": "Low", "attackVector": "Network", "author": "NVD", "availabilityImpact": "High", "baseScore": 8.8, "baseSeverity": "High", "confidentialityImpact": "High", "exploitabilityScore": null, "id": "CVE-2020-15969", "impactScore": null, "integrityImpact": "High", "privilegesRequired": "None", "scope": "Unchanged", "trust": 0.8, "userInteraction": "Required", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" } ], "severity": [ { "author": "nvd@nist.gov", "id": "CVE-2020-15969", "trust": 1.0, "value": "HIGH" }, { "author": "NVD", "id": "CVE-2020-15969", "trust": 0.8, "value": "High" }, { "author": "VULHUB", "id": "VHN-169000", "trust": 0.1, "value": "MEDIUM" } ] } ], "sources": [ { "db": "VULHUB", "id": "VHN-169000" }, { "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "db": "NVD", "id": "CVE-2020-15969" } ] }, "description": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/description#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Google Chrome Is vulnerable to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Google Chrome is a web browser developed by Google (Google). Chrome has security holes. -----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA256\n\nAPPLE-SA-2020-12-14-3 macOS Big Sur 11.1, Security Update 2020-001\nCatalina, Security Update 2020-007 Mojave\n\nmacOS Big Sur 11.1, Security Update 2020-001 Catalina, Security\nUpdate 2020-007 Mojave addresses the following issues. Information\nabout the security content is also available at\nhttps://support.apple.com/HT212011. \n\nAMD\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A malicious application may be able to execute arbitrary code\nwith system privileges\nDescription: A memory corruption issue was addressed with improved\ninput validation. \nCVE-2020-27914: Yu Wang of Didi Research America\nCVE-2020-27915: Yu Wang of Didi Research America\n\nApp Store\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An application may be able to gain elevated privileges\nDescription: This issue was addressed by removing the vulnerable\ncode. \nCVE-2020-27903: Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab\n\nAppleGraphicsControl\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: A validation issue was addressed with improved logic. \nCVE-2020-27941: shrek_wzw\n\nAppleMobileFileIntegrity\nAvailable for: macOS Big Sur 11.0.1\nImpact: A malicious application may be able to bypass Privacy\npreferences\nDescription: This issue was addressed with improved checks. \nCVE-2020-29621: Wojciech Regu\u0142a (@_r3ggi) of SecuRing\n\nAudio\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted audio file may lead to\narbitrary code execution\nDescription: An out-of-bounds read was addressed with improved input\nvalidation. \nCVE-2020-27910: JunDong Xie and XingWei Lin of Ant Security Light-\nYear Lab\n\nAudio\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A malicious application may be able to read restricted memory\nDescription: An out-of-bounds read was addressed with improved bounds\nchecking. \nCVE-2020-9943: JunDong Xie of Ant Security Light-Year Lab\n\nAudio\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An application may be able to read restricted memory\nDescription: An out-of-bounds read was addressed with improved bounds\nchecking. \nCVE-2020-9944: JunDong Xie of Ant Security Light-Year Lab\n\nAudio\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted audio file may lead to\narbitrary code execution\nDescription: An out-of-bounds write was addressed with improved input\nvalidation. \nCVE-2020-27916: JunDong Xie of Ant Security Light-Year Lab\n\nBluetooth\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A remote attacker may be able to cause unexpected application\ntermination or heap corruption\nDescription: Multiple integer overflows were addressed with improved\ninput validation. \nCVE-2020-27906: Zuozhi Fan (@pattern_F_) of Ant Group Tianqiong\nSecurity Lab\n\nCoreAudio\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: Processing a maliciously crafted audio file may lead to\narbitrary code execution\nDescription: An out-of-bounds write issue was addressed with improved\nbounds checking. \nCVE-2020-27948: JunDong Xie of Ant Security Light-Year Lab\n\nCoreAudio\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted audio file may lead to\narbitrary code execution\nDescription: An out-of-bounds read was addressed with improved input\nvalidation. \nCVE-2020-9960: JunDong Xie and XingWei Lin of Ant Security Light-Year\nLab\nCVE-2020-27908: JunDong Xie and XingWei Lin of Ant Security Light-\nYear Lab\n\nCoreAudio\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted audio file may lead to\narbitrary code execution\nDescription: An out-of-bounds write was addressed with improved input\nvalidation. \nCVE-2020-10017: Francis working with Trend Micro Zero Day Initiative,\nJunDong Xie of Ant Security Light-Year Lab\n\nCoreText\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted font file may lead to\narbitrary code execution\nDescription: A logic issue was addressed with improved state\nmanagement. \nCVE-2020-27922: Mickey Jin of Trend Micro\n\nFontParser\nAvailable for: macOS Big Sur 11.0.1\nImpact: Processing a maliciously crafted font may result in the\ndisclosure of process memory\nDescription: An information disclosure issue was addressed with\nimproved state management. \nCVE-2020-27946: Mateusz Jurczyk of Google Project Zero\n\nFontParser\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted image may lead to arbitrary\ncode execution\nDescription: A buffer overflow was addressed with improved size\nvalidation. \nCVE-2020-9962: Yi\u011fit Can YILMAZ (@yilmazcanyigit)\n\nFontParser\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted font file may lead to\narbitrary code execution\nDescription: An out-of-bounds write was addressed with improved input\nvalidation. \nCVE-2020-27952: an anonymous researcher, Mickey Jin and Junzhi Lu of\nTrend Micro\n\nFontParser\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted font file may lead to\narbitrary code execution\nDescription: An out-of-bounds read was addressed with improved input\nvalidation. \nCVE-2020-9956: Mickey Jin and Junzhi Lu of Trend Micro Mobile\nSecurity Research Team working with Trend Micro\u2019s Zero Day Initiative\n\nFontParser\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: Processing a maliciously crafted font file may lead to\narbitrary code execution\nDescription: A memory corruption issue existed in the processing of\nfont files. This issue was addressed with improved input validation. \nCVE-2020-27931: Apple\nCVE-2020-27943: Mateusz Jurczyk of Google Project Zero\nCVE-2020-27944: Mateusz Jurczyk of Google Project Zero\n\nFoundation\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A local user may be able to read arbitrary files\nDescription: A logic issue was addressed with improved state\nmanagement. \nCVE-2020-10002: James Hutchins\n\nGraphics Drivers\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: A memory corruption issue was addressed with improved\ninput validation. \nCVE-2020-27947: ABC Research s.r.o. working with Trend Micro Zero Day\nInitiative\n\nGraphics Drivers\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: A malicious application may be able to execute arbitrary code\nwith system privileges\nDescription: An out-of-bounds write issue was addressed with improved\nbounds checking. \nCVE-2020-29612: ABC Research s.r.o. working with Trend Micro Zero Day\nInitiative\n\nHomeKit\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An attacker in a privileged network position may be able to\nunexpectedly alter application state\nDescription: This issue was addressed with improved setting\npropagation. \nCVE-2020-9978: Luyi Xing, Dongfang Zhao, and Xiaofeng Wang of Indiana\nUniversity Bloomington, Yan Jia of Xidian University and University\nof Chinese Academy of Sciences, and Bin Yuan of HuaZhong University\nof Science and Technology\n\nImage Processing\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted image may lead to arbitrary\ncode execution\nDescription: An out-of-bounds write was addressed with improved input\nvalidation. \nCVE-2020-27919: Hou JingYi (@hjy79425575) of Qihoo 360 CERT, Xingwei\nLin of Ant Security Light-Year Lab\n\nImageIO\nAvailable for: macOS Big Sur 11.0.1\nImpact: Processing a maliciously crafted image may lead to arbitrary\ncode execution\nDescription: A memory corruption issue was addressed with improved\ninput validation. \nCVE-2020-29616: zhouat working with Trend Micro Zero Day Initiative\n\nImageIO\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: Processing a maliciously crafted image may lead to arbitrary\ncode execution\nDescription: An out-of-bounds read was addressed with improved input\nvalidation. \nCVE-2020-27924: Lei Sun\nCVE-2020-29618: XingWei Lin of Ant Security Light-Year Lab\n\nImageIO\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: Processing a maliciously crafted image may lead to arbitrary\ncode execution\nDescription: An out-of-bounds write issue was addressed with improved\nbounds checking. \nCVE-2020-29611: Ivan Fratric of Google Project Zero\n\nImageIO\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: Processing a maliciously crafted image may lead to heap\ncorruption\nDescription: An out-of-bounds read was addressed with improved input\nvalidation. \nCVE-2020-29617: XingWei Lin of Ant Security Light-Year Lab\nCVE-2020-29619: XingWei Lin of Ant Security Light-Year Lab\n\nImageIO\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted image may lead to arbitrary\ncode execution\nDescription: An out-of-bounds write was addressed with improved input\nvalidation. \nCVE-2020-27912: Xingwei Lin of Ant Security Light-Year Lab\nCVE-2020-27923: Lei Sun\n\nIntel Graphics Driver\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: An out-of-bounds write issue was addressed with improved\nbounds checking. \nCVE-2020-10015: ABC Research s.r.o. working with Trend Micro Zero Day\nInitiative\nCVE-2020-27897: Xiaolong Bai and Min (Spark) Zheng of Alibaba Inc. \nand Luyi Xing of Indiana University Bloomington\n\nIntel Graphics Driver\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: A memory corruption issue was addressed with improved\nmemory handling. \nCVE-2020-27907: ABC Research s.r.o. working with Trend Micro Zero Day\nInitiative\n\nKernel\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A malicious application may be able to determine kernel\nmemory layout\nDescription: A logic issue was addressed with improved state\nmanagement. \nCVE-2020-9974: Tommy Muir (@Muirey03)\n\nKernel\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: A memory corruption issue was addressed with improved\nstate management. \nCVE-2020-10016: Alex Helie\n\nKernel\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A remote attacker may be able to cause unexpected system\ntermination or corrupt kernel memory\nDescription: Multiple memory corruption issues were addressed with\nimproved input validation. \nCVE-2020-9967: Alex Plaskett (@alexjplaskett)\n\nKernel\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: A use after free issue was addressed with improved\nmemory management. \nCVE-2020-9975: Tielei Wang of Pangu Lab\n\nKernel\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: A race condition was addressed with improved state\nhandling. \nCVE-2020-27921: Linus Henze (pinauten.de)\n\nKernel\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7, macOS\nBig Sur 11.0.1\nImpact: A malicious application may cause unexpected changes in\nmemory belonging to processes traced by DTrace\nDescription: This issue was addressed with improved checks to prevent\nunauthorized actions. \nCVE-2020-27949: Steffen Klee (@_kleest) of TU Darmstadt, Secure\nMobile Networking Lab\n\nKernel\nAvailable for: macOS Big Sur 11.0.1\nImpact: A malicious application may be able to elevate privileges\nDescription: This issue was addressed with improved entitlements. \nCVE-2020-29620: Csaba Fitzl (@theevilbit) of Offensive Security\n\nlibxml2\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A remote attacker may be able to cause unexpected application\ntermination or arbitrary code execution\nDescription: An integer overflow was addressed through improved input\nvalidation. \nCVE-2020-27911: found by OSS-Fuzz\n\nlibxml2\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing maliciously crafted web content may lead to code\nexecution\nDescription: A use after free issue was addressed with improved\nmemory management. \nCVE-2020-27920: found by OSS-Fuzz\n\nlibxml2\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing maliciously crafted web content may lead to\narbitrary code execution\nDescription: A use after free issue was addressed with improved\nmemory management. \nCVE-2020-27926: found by OSS-Fuzz\n\nlibxpc\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A malicious application may be able to break out of its\nsandbox\nDescription: A parsing issue in the handling of directory paths was\naddressed with improved path validation. \nCVE-2020-10014: Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab\n\nLogging\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A local attacker may be able to elevate their privileges\nDescription: A path handling issue was addressed with improved\nvalidation. \nCVE-2020-10010: Tommy Muir (@Muirey03)\n\nModel I/O\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted USD file may lead to\nunexpected application termination or arbitrary code execution\nDescription: An out-of-bounds read was addressed with improved input\nvalidation. \nCVE-2020-13524: Aleksandar Nikolic of Cisco Talos\n\nModel I/O\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Opening a maliciously crafted file may lead to unexpected\napplication termination or arbitrary code execution\nDescription: A logic issue was addressed with improved state\nmanagement. \nCVE-2020-10004: Aleksandar Nikolic of Cisco Talos\n\nNSRemoteView\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A sandboxed process may be able to circumvent sandbox\nrestrictions\nDescription: A logic issue was addressed with improved restrictions. \nCVE-2020-27901: Thijs Alkemade of Computest Research Division\n\nPower Management\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A malicious application may be able to determine kernel\nmemory layout\nDescription: A logic issue was addressed with improved state\nmanagement. \nCVE-2020-10007: singi@theori working with Trend Micro Zero Day\nInitiative\n\nQuick Look\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: Processing a maliciously crafted document may lead to a cross\nsite scripting attack\nDescription: An access issue was addressed with improved access\nrestrictions. \nCVE-2020-10012: Heige of KnownSec 404 Team (knownsec.com) and Bo Qu\nof Palo Alto Networks (paloaltonetworks.com)\n\nRuby\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A remote attacker may be able to modify the file system\nDescription: A path handling issue was addressed with improved\nvalidation. \nCVE-2020-27896: an anonymous researcher\n\nSystem Preferences\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: A sandboxed process may be able to circumvent sandbox\nrestrictions\nDescription: A logic issue was addressed with improved state\nmanagement. \nCVE-2020-10009: Thijs Alkemade of Computest Research Division\n\nWebRTC\nAvailable for: macOS Big Sur 11.0.1\nImpact: Processing maliciously crafted web content may lead to\narbitrary code execution\nDescription: A use after free issue was addressed with improved\nmemory management. \nCVE-2020-15969: an anonymous researcher\n\nWi-Fi\nAvailable for: macOS Mojave 10.14.6, macOS Catalina 10.15.7\nImpact: An attacker may be able to bypass Managed Frame Protection\nDescription: A denial of service issue was addressed with improved\nstate handling. \nCVE-2020-27898: Stephan Marais of University of Johannesburg\n\nInstallation note:\n\nmacOS Big Sur 11.1, Security Update 2020-001 Catalina, Security\nUpdate 2020-007 Mojave may be obtained from the Mac App Store or\nApple\u0027s Software Downloads web site:\nhttps://support.apple.com/downloads/\n\nInformation will also be posted to the Apple Security Updates\nweb site: https://support.apple.com/kb/HT201222\n\nThis message is signed with Apple\u0027s Product Security PGP key,\nand details are available at:\nhttps://www.apple.com/support/security/pgp/\n-----BEGIN PGP SIGNATURE-----\n\niQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAl/YBj8ACgkQZcsbuWJ6\njjCVjw//QGrhMvU+nyuS1UwWs7rcqDJDNh0Zb7yUJali2Bdc9/l++i2pLFbmAwes\n7AYCag+T3h3aP7YJAN13zb8KBmUcmnWkWupfx8kEGqHxSXnQTXvaEI59RyCobOCj\nOVPtboPMH1d94+6dABMp9kiLAHoZezm3hdF8ShT2Hqgq2TB16wZsa/EvhJVSaduA\n7RttG6EHBTin6UU3M/+vcfJWqkg4O0YuZpQaconDa5Pd81jpUMeduzfRvS5i+PVS\ncehtHPWjCN15+sQ29q11yhP3v+sYh0DJEl2LWaBnDo2TlC1gHx70H5ZsAFLHChcd\nrXkl1tm6GV3UWVhFq0jQc1DP+IwbuL6jHI/wIjYx7itk9XECppyhhiuImOaLiIUH\nCBgAjwVHY1GUdTH97iPEQFF61v3sjpRLleLMZW7+9ZTt4pEDwMVHk9vKgVK5BUa6\nlrKWtBHL3AtaXtxC9y8XGe3IYEBLAszHMUJfF1BR+D/niDRlztvoj72/3PPwtk2t\ntuUE9RGzpSXCQ1CX6vW7zS2ddVmQfJqcPX721k4OVpFNlMXkjZkm2Q/xwr5qq99v\nUp9BA+ITksthGYfGAY5bBV1LsjK1NtdNHQGpZe4l9bu4ONgUvmL8iBb/LnS6wKB1\nHGcdHEmXvbx+Akl/fvTdG8RSvyoYuFJHkuYv0DMWiri8yN1q+C4=\n=osnP\n-----END PGP SIGNATURE-----\n\n\n. 8.1) - aarch64, ppc64le, s390x, x86_64\n\n3. 8) - aarch64, ppc64le, x86_64\n\n3. Summary:\n\nAn update for chromium-browser is now available for Red Hat Enterprise\nLinux 6 Supplementary. \n\nRed Hat Product Security has rated this update as having a security impact\nof Critical. A Common Vulnerability Scoring System (CVSS) base score, which\ngives a detailed severity rating, is available for each vulnerability from\nthe CVE link(s) in the References section. \n\n2. Relevant releases/architectures:\n\nRed Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, i686, x86_64\nRed Hat Enterprise Linux HPC Node Supplementary (v. 6) - i686, x86_64\nRed Hat Enterprise Linux Server Supplementary (v. 6) - i386, i686, x86_64\nRed Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, i686, x86_64\n\n3. Description:\n\nChromium is an open-source web browser, powered by WebKit (Blink). \n\nThis update upgrades Chromium to version 86.0.4240.75. \n\nSecurity Fix(es):\n\n* chromium-browser: Use after free in payments (CVE-2020-15967)\n\n* chromium-browser: Use after free in Blink (CVE-2020-15968)\n\n* chromium-browser: Use after free in WebRTC (CVE-2020-15969)\n\n* chromium-browser: Use after free in NFC (CVE-2020-15970)\n\n* chromium-browser: Use after free in printing (CVE-2020-15971)\n\n* chromium-browser: Use after free in audio (CVE-2020-15972)\n\n* chromium-browser: Use after free in autofill (CVE-2020-15990)\n\n* chromium-browser: Use after free in password manager (CVE-2020-15991)\n\n* chromium-browser: Inappropriate implementation in networking\n(CVE-2020-6557)\n\n* chromium-browser: Insufficient policy enforcement in extensions\n(CVE-2020-15973)\n\n* chromium-browser: Integer overflow in Blink (CVE-2020-15974)\n\n* chromium-browser: Integer overflow in SwiftShader (CVE-2020-15975)\n\n* chromium-browser: Use after free in WebXR (CVE-2020-15976)\n\n* chromium-browser: Insufficient data validation in dialogs\n(CVE-2020-15977)\n\n* chromium-browser: Insufficient data validation in navigation\n(CVE-2020-15978)\n\n* chromium-browser: Inappropriate implementation in V8 (CVE-2020-15979)\n\n* chromium-browser: Insufficient policy enforcement in Intents\n(CVE-2020-15980)\n\n* chromium-browser: Out of bounds read in audio (CVE-2020-15981)\n\n* chromium-browser: Side-channel information leakage in cache\n(CVE-2020-15982)\n\n* chromium-browser: Insufficient data validation in webUI (CVE-2020-15983)\n\n* chromium-browser: Insufficient policy enforcement in Omnibox\n(CVE-2020-15984)\n\n* chromium-browser: Inappropriate implementation in Blink (CVE-2020-15985)\n\n* chromium-browser: Integer overflow in media (CVE-2020-15986)\n\n* chromium-browser: Use after free in WebRTC (CVE-2020-15987)\n\n* chromium-browser: Insufficient policy enforcement in networking\n(CVE-2020-15992)\n\n* chromium-browser: Insufficient policy enforcement in downloads\n(CVE-2020-15988)\n\n* chromium-browser: Uninitialized use in PDFium (CVE-2020-15989)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, acknowledgments, and other related information, refer to the CVE\npage(s) listed in the References section. \n\n4. Solution:\n\nFor details on how to apply this update, which includes the changes\ndescribed in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to\ntake effect. \n\n5. Bugs fixed (https://bugzilla.redhat.com/):\n\n1885883 - CVE-2020-15967 chromium-browser: Use after free in payments\n1885884 - CVE-2020-15968 chromium-browser: Use after free in Blink\n1885885 - CVE-2020-15969 chromium-browser: Use after free in WebRTC\n1885886 - CVE-2020-15970 chromium-browser: Use after free in NFC\n1885887 - CVE-2020-15971 chromium-browser: Use after free in printing\n1885888 - CVE-2020-15972 chromium-browser: Use after free in audio\n1885889 - CVE-2020-15990 chromium-browser: Use after free in autofill\n1885890 - CVE-2020-15991 chromium-browser: Use after free in password manager\n1885891 - CVE-2020-15973 chromium-browser: Insufficient policy enforcement in extensions\n1885892 - CVE-2020-15974 chromium-browser: Integer overflow in Blink\n1885893 - CVE-2020-15975 chromium-browser: Integer overflow in SwiftShader\n1885894 - CVE-2020-15976 chromium-browser: Use after free in WebXR\n1885896 - CVE-2020-6557 chromium-browser: Inappropriate implementation in networking\n1885897 - CVE-2020-15977 chromium-browser: Insufficient data validation in dialogs\n1885899 - CVE-2020-15978 chromium-browser: Insufficient data validation in navigation\n1885901 - CVE-2020-15979 chromium-browser: Inappropriate implementation in V8\n1885902 - CVE-2020-15980 chromium-browser: Insufficient policy enforcement in Intents\n1885903 - CVE-2020-15981 chromium-browser: Out of bounds read in audio\n1885904 - CVE-2020-15982 chromium-browser: Side-channel information leakage in cache\n1885905 - CVE-2020-15983 chromium-browser: Insufficient data validation in webUI\n1885906 - CVE-2020-15984 chromium-browser: Insufficient policy enforcement in Omnibox\n1885907 - CVE-2020-15985 chromium-browser: Inappropriate implementation in Blink\n1885908 - CVE-2020-15986 chromium-browser: Integer overflow in media\n1885909 - CVE-2020-15987 chromium-browser: Use after free in WebRTC\n1885910 - CVE-2020-15992 chromium-browser: Insufficient policy enforcement in networking\n1885911 - CVE-2020-15988 chromium-browser: Insufficient policy enforcement in downloads\n1885912 - CVE-2020-15989 chromium-browser: Uninitialized use in PDFium\n\n6. Package List:\n\nRed Hat Enterprise Linux Desktop Supplementary (v. 6):\n\ni386:\nchromium-browser-86.0.4240.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm\n\ni686:\nchromium-browser-86.0.4240.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm\n\nx86_64:\nchromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm\n\nRed Hat Enterprise Linux HPC Node Supplementary (v. 6):\n\ni686:\nchromium-browser-86.0.4240.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm\n\nx86_64:\nchromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm\n\nRed Hat Enterprise Linux Server Supplementary (v. 6):\n\ni386:\nchromium-browser-86.0.4240.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm\n\ni686:\nchromium-browser-86.0.4240.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm\n\nx86_64:\nchromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm\n\nRed Hat Enterprise Linux Workstation Supplementary (v. 6):\n\ni386:\nchromium-browser-86.0.4240.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm\n\ni686:\nchromium-browser-86.0.4240.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.i686.rpm\n\nx86_64:\nchromium-browser-86.0.4240.75-1.el6_10.x86_64.rpm\nchromium-browser-debuginfo-86.0.4240.75-1.el6_10.x86_64.rpm\n\nThese packages are GPG signed by Red Hat for security. Our key and\ndetails on how to verify the signature are available from\nhttps://access.redhat.com/security/team/key/\n\n7. References:\n\nhttps://access.redhat.com/security/cve/CVE-2020-6557\nhttps://access.redhat.com/security/cve/CVE-2020-15967\nhttps://access.redhat.com/security/cve/CVE-2020-15968\nhttps://access.redhat.com/security/cve/CVE-2020-15969\nhttps://access.redhat.com/security/cve/CVE-2020-15970\nhttps://access.redhat.com/security/cve/CVE-2020-15971\nhttps://access.redhat.com/security/cve/CVE-2020-15972\nhttps://access.redhat.com/security/cve/CVE-2020-15973\nhttps://access.redhat.com/security/cve/CVE-2020-15974\nhttps://access.redhat.com/security/cve/CVE-2020-15975\nhttps://access.redhat.com/security/cve/CVE-2020-15976\nhttps://access.redhat.com/security/cve/CVE-2020-15977\nhttps://access.redhat.com/security/cve/CVE-2020-15978\nhttps://access.redhat.com/security/cve/CVE-2020-15979\nhttps://access.redhat.com/security/cve/CVE-2020-15980\nhttps://access.redhat.com/security/cve/CVE-2020-15981\nhttps://access.redhat.com/security/cve/CVE-2020-15982\nhttps://access.redhat.com/security/cve/CVE-2020-15983\nhttps://access.redhat.com/security/cve/CVE-2020-15984\nhttps://access.redhat.com/security/cve/CVE-2020-15985\nhttps://access.redhat.com/security/cve/CVE-2020-15986\nhttps://access.redhat.com/security/cve/CVE-2020-15987\nhttps://access.redhat.com/security/cve/CVE-2020-15988\nhttps://access.redhat.com/security/cve/CVE-2020-15989\nhttps://access.redhat.com/security/cve/CVE-2020-15990\nhttps://access.redhat.com/security/cve/CVE-2020-15991\nhttps://access.redhat.com/security/cve/CVE-2020-15992\nhttps://access.redhat.com/security/updates/classification/#critical\n\n8. Contact:\n\nThe Red Hat security contact is \u003csecalert@redhat.com\u003e. More contact\ndetails at https://access.redhat.com/security/team/contact/\n\nCopyright 2020 Red Hat, Inc. \n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1\n\niQIVAwUBX4VjutzjgjWX9erEAQiBog/8D4EAnQmD6yqmkt9gVgCzoz1v/uOgnTHv\nlghXbEidNiTmb8DlvwZKbqA/2wz/kz+vW5v0bXZNjngYnbZsev252qT9L2LQ99UA\n+uirPF/zddn+T0tZ5PQHWBYpWgjF8XRQu7lJo7QHbB7GEMXJJ4SBN3erYqOjKKUo\n3DakSX4DH1VIrSY+6kJ6fx26IwD7tWSBlsRklatxX1NkhrBg0Ha7lWjHhRV6WLjz\nCZFxwFNJJ6bGsf8eIaaps8Ab21m87BbwOyGt2aaFT9sC5noR4mTTjBGB4lmbslB3\nVcl7PSxqs/AzDK6fAqLOJ7nqZJpiQq9ii5Z3oBbiG3J8BO6sgY7cG+D2bVWD+3eV\n9L13REiW/iPXqGbpgPre8WhAwg3wdNYDiaYO6pIC7N1a/btxIdq5Gjb31dWiFdyq\nXOtdEO9CieZGYNEoKf+wfe03SXCEvJz0EZZVwcFhqd8cF8xhUa2MNjpKDHryUjXg\n8rJGA+5uS/UJHwToK++Q4+0Ze/jIxSuKRA7h9UhdACksgeMmFUdyfuLVfx1RdgEX\nTRtO8kHaGBHz60SY4Kd6xkZks1+FqotFF2zvs4gq8XvPFbHvPgt36qbtxOHYj1BF\npl+WqaRsDOp6VmbMLAEJwZnRsR0dNN62MCgxB5sNRb5l7sSYOqYClV2zR47cEgFJ\nObQiF6iTAHk=AItV\n-----END PGP SIGNATURE-----\n\n--\nRHSA-announce mailing list\nRHSA-announce@redhat.com\nhttps://www.redhat.com/mailman/listinfo/rhsa-announce\n. 7) - x86_64\n\n3. Description:\n\nMozilla Thunderbird is a standalone mail and newsgroup client. \n\nSecurity Fix(es):\n\n* Mozilla: Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4\n(CVE-2020-15683)\n\n* chromium-browser: Use after free in WebRTC (CVE-2020-15969)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, acknowledgments, and other related information, refer to the CVE\npage(s) listed in the References section. Bugs fixed (https://bugzilla.redhat.com/):\n\n1885885 - CVE-2020-15969 chromium-browser: Use after free in WebRTC\n1889932 - CVE-2020-15683 Mozilla: Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4\n\n6. \n\nFor the stable distribution (buster), these problems have been fixed in\nversion 78.4.0esr-1~deb10u2. \n\nWe recommend that you upgrade your firefox-esr packages", "sources": [ { "db": "NVD", "id": "CVE-2020-15969" }, { "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "db": "VULHUB", "id": "VHN-169000" }, { "db": "VULMON", "id": "CVE-2020-15969" }, { "db": "PACKETSTORM", "id": "159686" }, { "db": "PACKETSTORM", "id": "160538" }, { "db": "PACKETSTORM", "id": "159683" }, { "db": "PACKETSTORM", "id": "159888" }, { "db": "PACKETSTORM", "id": "159536" }, { "db": "PACKETSTORM", "id": "159893" }, { "db": "PACKETSTORM", "id": "168916" } ], "trust": 2.43 }, "external_ids": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/external_ids#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "db": "NVD", "id": "CVE-2020-15969", "trust": 2.8 }, { "db": "JVNDB", "id": "JVNDB-2020-013002", "trust": 0.8 }, { "db": "PACKETSTORM", "id": "159893", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "159683", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "160538", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "159536", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "159888", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "159686", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "159909", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159910", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "160543", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "161131", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159679", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159695", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159906", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "160536", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159587", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "160542", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159907", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "160540", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159746", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "159682", "trust": 0.1 }, { "db": "VULHUB", "id": "VHN-169000", "trust": 0.1 }, { "db": "VULMON", "id": "CVE-2020-15969", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "168970", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "168916", "trust": 0.1 } ], "sources": [ { "db": "VULHUB", "id": "VHN-169000" }, { "db": "VULMON", "id": "CVE-2020-15969" }, { "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "db": "PACKETSTORM", "id": "159686" }, { "db": "PACKETSTORM", "id": "160538" }, { "db": "PACKETSTORM", "id": "159683" }, { "db": "PACKETSTORM", "id": "159888" }, { "db": "PACKETSTORM", "id": "159536" }, { "db": "PACKETSTORM", "id": "159893" }, { "db": "PACKETSTORM", "id": "168970" }, { "db": "PACKETSTORM", "id": "168916" }, { "db": "NVD", "id": "CVE-2020-15969" } ] }, "id": "VAR-202011-0444", "iot": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/iot#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": true, "sources": [ { "db": "VULHUB", "id": "VHN-169000" } ], "trust": 0.01 }, "last_update_date": "2024-09-19T21:29:57.888000Z", "patch": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/patch#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "title": "HT212011", "trust": 0.8, "url": "https://www.debian.org/security/2021/dsa-4824" }, { "title": "Arch Linux Issues: ", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=arch_linux_issues\u0026qid=CVE-2020-15969 log" }, { "title": "Red Hat: Critical: chromium-browser security update", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories\u0026qid=RHSA-20204235 - Security Advisory" }, { "title": "Arch Linux Advisories: [ASA-202010-1] chromium: multiple issues", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories\u0026qid=ASA-202010-1" }, { "title": "Google Chrome: Stable Channel Update for Desktop", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=chrome_releases\u0026qid=19864a55e2d45827624ffa261a77ce92" }, { "title": "Threatpost", "trust": 0.1, "url": "https://threatpost.com/google-chrome-86-critical-payments-bug-password-check/159938/" } ], "sources": [ { "db": "VULMON", "id": "CVE-2020-15969" }, { "db": "JVNDB", "id": "JVNDB-2020-013002" } ] }, "problemtype_data": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/problemtype_data#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "problemtype": "CWE-416", "trust": 1.1 }, { "problemtype": "CWE-787", "trust": 1.1 }, { "problemtype": "Use of freed memory (CWE-416) [NVD Evaluation ]", "trust": 0.8 } ], "sources": [ { "db": "VULHUB", "id": "VHN-169000" }, { "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "db": "NVD", "id": "CVE-2020-15969" } ] }, "references": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/references#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "trust": 1.6, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15969" }, { "trust": 1.2, "url": "https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html" }, { "trust": 1.2, "url": "https://crbug.com/1124659" }, { "trust": 1.1, "url": "https://support.apple.com/kb/ht212003" }, { "trust": 1.1, "url": "https://support.apple.com/kb/ht212005" }, { "trust": 1.1, "url": "https://support.apple.com/kb/ht212007" }, { "trust": 1.1, "url": "https://support.apple.com/kb/ht212009" }, { "trust": 1.1, "url": "https://support.apple.com/kb/ht212011" }, { "trust": 1.1, "url": "https://www.debian.org/security/2021/dsa-4824" }, { "trust": 1.1, "url": "http://seclists.org/fulldisclosure/2020/dec/24" }, { "trust": 1.1, "url": "http://seclists.org/fulldisclosure/2020/dec/26" }, { "trust": 1.1, "url": "http://seclists.org/fulldisclosure/2020/dec/27" }, { "trust": 1.1, "url": "http://seclists.org/fulldisclosure/2020/dec/29" }, { "trust": 1.1, "url": "http://seclists.org/fulldisclosure/2020/dec/30" }, { "trust": 1.1, "url": "https://security.gentoo.org/glsa/202101-30" }, { "trust": 1.1, "url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html" }, { "trust": 1.0, "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/24qfl4c3azkmfvl7lvsymu2dne5vvugs/" }, { "trust": 1.0, "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4gwcwnhttyoh6hsfuxpgpbb6j6jyzhze/" }, { "trust": 1.0, "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/sc3u3h6aisvzb5plzllnf4hmq4uffl7m/" }, { "trust": 0.5, "url": "https://www.redhat.com/mailman/listinfo/rhsa-announce" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15683" }, { "trust": 0.5, "url": "https://access.redhat.com/security/cve/cve-2020-15969" }, { "trust": 0.5, "url": "https://bugzilla.redhat.com/):" }, { "trust": 0.5, "url": "https://access.redhat.com/security/team/key/" }, { "trust": 0.5, "url": "https://access.redhat.com/articles/11258" }, { "trust": 0.5, "url": "https://access.redhat.com/security/team/contact/" }, { "trust": 0.4, "url": "https://access.redhat.com/security/cve/cve-2020-15683" }, { "trust": 0.4, "url": "https://access.redhat.com/security/updates/classification/#important" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15968" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15971" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15970" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15967" }, { "trust": 0.2, "url": "https://www.debian.org/security/faq" }, { "trust": 0.2, "url": "https://www.debian.org/security/" }, { "trust": 0.1, "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4gwcwnhttyoh6hsfuxpgpbb6j6jyzhze/" }, { "trust": 0.1, "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/sc3u3h6aisvzb5plzllnf4hmq4uffl7m/" }, { "trust": 0.1, "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/24qfl4c3azkmfvl7lvsymu2dne5vvugs/" }, { "trust": 0.1, "url": "https://nvd.nist.gov" }, { "trust": 0.1, "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/189465" }, { "trust": 0.1, "url": "https://threatpost.com/google-chrome-86-critical-payments-bug-password-check/159938/" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2020:4317" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10014" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-13524" }, { "trust": 0.1, "url": "https://support.apple.com/kb/ht201222" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27903" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10016" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27910" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27897" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27907" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10015" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10017" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27912" }, { "trust": 0.1, "url": "https://support.apple.com/downloads/" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27901" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27896" }, { "trust": 0.1, "url": "https://support.apple.com/ht212011." }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27898" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27914" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27908" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27911" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10009" }, { "trust": 0.1, "url": "https://www.apple.com/support/security/pgp/" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27915" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10004" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10002" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27916" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10010" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10012" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-27906" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10007" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2020:4315" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2020:4913" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2020:4235" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15972" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15990" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15974" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15971" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15968" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15984" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15986" }, { "trust": 0.1, "url": "https://access.redhat.com/security/updates/classification/#critical" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15972" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15973" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15977" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15987" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15979" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15989" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15988" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15978" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15989" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15983" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15991" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15987" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15970" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-6557" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15973" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15975" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15978" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15977" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15981" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15988" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15985" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15984" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15992" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15980" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15975" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15980" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15982" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15974" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15985" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15976" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15982" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15967" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15992" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15981" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15983" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15976" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15991" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15990" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15979" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15986" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2020:4909" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15966" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15960" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15959" }, { "trust": 0.1, "url": "https://security-tracker.debian.org/tracker/chromium" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15963" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15962" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15964" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15965" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15961" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-8075" }, { "trust": 0.1, "url": "https://security-tracker.debian.org/tracker/firefox-esr" } ], "sources": [ { "db": "VULHUB", "id": "VHN-169000" }, { "db": "VULMON", "id": "CVE-2020-15969" }, { "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "db": "PACKETSTORM", "id": "159686" }, { "db": "PACKETSTORM", "id": "160538" }, { "db": "PACKETSTORM", "id": "159683" }, { "db": "PACKETSTORM", "id": "159888" }, { "db": "PACKETSTORM", "id": "159536" }, { "db": "PACKETSTORM", "id": "159893" }, { "db": "PACKETSTORM", "id": "168970" }, { "db": "PACKETSTORM", "id": "168916" }, { "db": "NVD", "id": "CVE-2020-15969" } ] }, "sources": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#", "data": { "@container": "@list" } }, "data": [ { "db": "VULHUB", "id": "VHN-169000" }, { "db": "VULMON", "id": "CVE-2020-15969" }, { "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "db": "PACKETSTORM", "id": "159686" }, { "db": "PACKETSTORM", "id": "160538" }, { "db": "PACKETSTORM", "id": "159683" }, { "db": "PACKETSTORM", "id": "159888" }, { "db": "PACKETSTORM", "id": "159536" }, { "db": "PACKETSTORM", "id": "159893" }, { "db": "PACKETSTORM", "id": "168970" }, { "db": "PACKETSTORM", "id": "168916" }, { "db": "NVD", "id": "CVE-2020-15969" } ] }, "sources_release_date": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources_release_date#", "data": { "@container": "@list" } }, "data": [ { "date": "2020-11-03T00:00:00", "db": "VULHUB", "id": "VHN-169000" }, { "date": "2020-11-03T00:00:00", "db": "VULMON", "id": "CVE-2020-15969" }, { "date": "2021-06-16T00:00:00", "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "date": "2020-10-22T23:56:11", "db": "PACKETSTORM", "id": "159686" }, { "date": "2020-12-16T17:58:29", "db": "PACKETSTORM", "id": "160538" }, { "date": "2020-10-22T23:55:51", "db": "PACKETSTORM", "id": "159683" }, { "date": "2020-11-04T15:34:38", "db": "PACKETSTORM", "id": "159888" }, { "date": "2020-10-13T20:24:04", "db": "PACKETSTORM", "id": "159536" }, { "date": "2020-11-04T15:35:33", "db": "PACKETSTORM", "id": "159893" }, { "date": "2021-01-28T20:12:00", "db": "PACKETSTORM", "id": "168970" }, { "date": "2020-10-28T19:12:00", "db": "PACKETSTORM", "id": "168916" }, { "date": "2020-11-03T03:15:12.790000", "db": "NVD", "id": "CVE-2020-15969" } ] }, "sources_update_date": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources_update_date#", "data": { "@container": "@list" } }, "data": [ { "date": "2021-07-21T00:00:00", "db": "VULHUB", "id": "VHN-169000" }, { "date": "2021-01-30T00:00:00", "db": "VULMON", "id": "CVE-2020-15969" }, { "date": "2021-06-16T09:01:00", "db": "JVNDB", "id": "JVNDB-2020-013002" }, { "date": "2023-11-07T03:17:58.410000", "db": "NVD", "id": "CVE-2020-15969" } ] }, "title": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/title#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "Google\u00a0Chrome\u00a0 Vulnerabilities in the use of freed memory", "sources": [ { "db": "JVNDB", "id": "JVNDB-2020-013002" } ], "trust": 0.8 }, "type": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/type#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "overflow, code execution", "sources": [ { "db": "PACKETSTORM", "id": "160538" } ], "trust": 0.1 } }
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.