CVE-2020-0514
published 2020-03-12CVE-2020-0514: Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.0th percentile
Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | >= 15.45 < 15.45.30.5103 | 15.45.30.5103 |
| intel | graphics_driver | >= 26.20 < 26.20.100.7463 | 26.20.100.7463 |
| intel | intel_graphics_drivers | — | — |
| intel | intel_graphics_drivers | — | — |
| intel | intel_graphics_drivers | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6389 chromium-browser: Out of bounds write in WebRTC
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6389 [HIGH] CVE-2020-6389 chromium-browser: Out of bounds write in WebRTC
CVE-2020-6389 chromium-browser: Out of bounds write in WebRTC
An out of bounds write flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1042933
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6389
Bugzilla
CVE-2020-6396 chromium-browser: Inappropriate implementation in Skia
bugzilla·2020-02-10·CVSS 4.3
CVE-2020-6396 [MEDIUM] CVE-2020-6396 chromium-browser: Inappropriate implementation in Skia
CVE-2020-6396 chromium-browser: Inappropriate implementation in Skia
An inappropriate implementation flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1035271
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cv
Bugzilla
CVE-2020-6391 chromium-browser: Insufficient validation of untrusted input in Blink
bugzilla·2020-02-10·CVSS 4.3
CVE-2020-6391 [MEDIUM] CVE-2020-6391 chromium-browser: Insufficient validation of untrusted input in Blink
CVE-2020-6391 chromium-browser: Insufficient validation of untrusted input in Blink
An insufficient validation of untrusted input flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1017871
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://acc
Bugzilla
CVE-2020-6408 chromium-browser: Insufficient policy enforcement in CORS
bugzilla·2020-02-10·CVSS 6.5
CVE-2020-6408 [MEDIUM] CVE-2020-6408 chromium-browser: Insufficient policy enforcement in CORS
CVE-2020-6408 chromium-browser: Insufficient policy enforcement in CORS
An insufficient policy enforcement flaw was found in the CORS component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1026546
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/
Bugzilla
CVE-2020-6385 chromium-browser: Insufficient policy enforcement in storage
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6385 [HIGH] CVE-2020-6385 chromium-browser: Insufficient policy enforcement in storage
CVE-2020-6385 chromium-browser: Insufficient policy enforcement in storage
An insufficient policy enforcement flaw was found in the storage component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1035399
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/sec
Bugzilla
CVE-2020-6411 chromium-browser: Insufficient validation of untrusted input in Omnibox
bugzilla·2020-02-10·CVSS 5.4
CVE-2020-6411 [MEDIUM] CVE-2020-6411 chromium-browser: Insufficient validation of untrusted input in Omnibox
CVE-2020-6411 chromium-browser: Insufficient validation of untrusted input in Omnibox
An insufficient validation of untrusted input flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=929711
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://
Bugzilla
CVE-2020-6397 chromium-browser: Incorrect security UI in sharing
bugzilla·2020-02-10·CVSS 6.5
CVE-2020-6397 [MEDIUM] CVE-2020-6397 chromium-browser: Incorrect security UI in sharing
CVE-2020-6397 chromium-browser: Incorrect security UI in sharing
An incorrect security ui flaw was found in the sharing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1027408
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6
Bugzilla
CVE-2020-6416 chromium-browser: Insufficient data validation in streams
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6416 [HIGH] CVE-2020-6416 chromium-browser: Insufficient data validation in streams
CVE-2020-6416 chromium-browser: Insufficient data validation in streams
An insufficient data validation flaw was found in the streams component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1031895
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/
Bugzilla
CVE-2020-6387 chromium-browser: Out of bounds write in WebRTC
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6387 [HIGH] CVE-2020-6387 chromium-browser: Out of bounds write in WebRTC
CVE-2020-6387 chromium-browser: Out of bounds write in WebRTC
An out of bounds write flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1042535
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6387
Bugzilla
CVE-2020-6406 chromium-browser: Use after free in audio
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6406 [HIGH] CVE-2020-6406 chromium-browser: Use after free in audio
CVE-2020-6406 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1042254
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6406
Bugzilla
CVE-2020-6381 chromium-browser: Integer overflow in JavaScript
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6381 [HIGH] CVE-2020-6381 chromium-browser: Integer overflow in JavaScript
CVE-2020-6381 chromium-browser: Integer overflow in JavaScript
An integer overflow flaw was found in the JavaScript component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1034394
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA
Bugzilla
CVE-2020-6392 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-02-10·CVSS 4.3
CVE-2020-6392 [MEDIUM] CVE-2020-6392 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-6392 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1030411
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
Bugzilla
CVE-2020-6413 chromium-browser: Inappropriate implementation in Blink
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6413 [HIGH] CVE-2020-6413 chromium-browser: Inappropriate implementation in Blink
CVE-2020-6413 chromium-browser: Inappropriate implementation in Blink
An inappropriate implementation flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1005713
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/
Bugzilla
CVE-2020-6395 chromium-browser: Out of bounds read in JavaScript
bugzilla·2020-02-10·CVSS 6.5
CVE-2020-6395 [MEDIUM] CVE-2020-6395 chromium-browser: Out of bounds read in JavaScript
CVE-2020-6395 chromium-browser: Out of bounds read in JavaScript
An out of bounds read flaw was found in the JavaScript component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1022855
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6
Bugzilla
CVE-2020-6382 chromium-browser: Type Confusion in JavaScript
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6382 [HIGH] CVE-2020-6382 chromium-browser: Type Confusion in JavaScript
CVE-2020-6382 chromium-browser: Type Confusion in JavaScript
A type confusion flaw was found in the JavaScript component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1031909
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6382
Bugzilla
CVE-2020-6394 chromium-browser: Insufficient policy enforcement in Blink
bugzilla·2020-02-10·CVSS 5.4
CVE-2020-6394 [MEDIUM] CVE-2020-6394 chromium-browser: Insufficient policy enforcement in Blink
CVE-2020-6394 chromium-browser: Insufficient policy enforcement in Blink
An insufficient policy enforcement flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1014371
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securit
Bugzilla
CVE-2020-6415 chromium-browser: Inappropriate implementation in JavaScript
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6415 [HIGH] CVE-2020-6415 chromium-browser: Inappropriate implementation in JavaScript
CVE-2020-6415 chromium-browser: Inappropriate implementation in JavaScript
An inappropriate implementation flaw was found in the JavaScript component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1029576
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/sec
Bugzilla
CVE-2020-6400 chromium-browser: Inappropriate implementation in CORS
bugzilla·2020-02-10·CVSS 6.5
CVE-2020-6400 [MEDIUM] CVE-2020-6400 chromium-browser: Inappropriate implementation in CORS
CVE-2020-6400 chromium-browser: Inappropriate implementation in CORS
An inappropriate implementation flaw was found in the CORS component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1038036
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cv
Bugzilla
CVE-2020-6393 chromium-browser: Insufficient policy enforcement in Blink
bugzilla·2020-02-10·CVSS 6.5
CVE-2020-6393 [MEDIUM] CVE-2020-6393 chromium-browser: Insufficient policy enforcement in Blink
CVE-2020-6393 chromium-browser: Insufficient policy enforcement in Blink
An insufficient policy enforcement flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1035058
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securit
Bugzilla
CVE-2020-6414 chromium-browser: Insufficient policy enforcement in Safe Browsing
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6414 [HIGH] CVE-2020-6414 chromium-browser: Insufficient policy enforcement in Safe Browsing
CVE-2020-6414 chromium-browser: Insufficient policy enforcement in Safe Browsing
An insufficient policy enforcement flaw was found in the Safe Browsing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1021855
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.re
Bugzilla
CVE-2020-6399 chromium-browser: Insufficient policy enforcement in AppCache
bugzilla·2020-02-10·CVSS 6.5
CVE-2020-6399 [MEDIUM] CVE-2020-6399 chromium-browser: Insufficient policy enforcement in AppCache
CVE-2020-6399 chromium-browser: Insufficient policy enforcement in AppCache
An insufficient policy enforcement flaw was found in the AppCache component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1039869
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/s
Bugzilla
CVE-2020-6398 chromium-browser: Uninitialized use in PDFium
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6398 [HIGH] CVE-2020-6398 chromium-browser: Uninitialized use in PDFium
CVE-2020-6398 chromium-browser: Uninitialized use in PDFium
An uninitialized use flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1032090
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6398
Bugzilla
CVE-2020-6412 chromium-browser: Insufficient validation of untrusted input in Omnibox
bugzilla·2020-02-10·CVSS 5.4
CVE-2020-6412 [MEDIUM] CVE-2020-6412 chromium-browser: Insufficient validation of untrusted input in Omnibox
CVE-2020-6412 chromium-browser: Insufficient validation of untrusted input in Omnibox
An insufficient validation of untrusted input flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=968505
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://
Bugzilla
CVE-2020-6409 chromium-browser: Inappropriate implementation in Omnibox
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6409 [HIGH] CVE-2020-6409 chromium-browser: Inappropriate implementation in Omnibox
CVE-2020-6409 chromium-browser: Inappropriate implementation in Omnibox
An inappropriate implementation flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1037889
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/
Bugzilla
CVE-2020-6403 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2020-02-10·CVSS 4.3
CVE-2020-6403 [MEDIUM] CVE-2020-6403 chromium-browser: Incorrect security UI in Omnibox
CVE-2020-6403 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1006012
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6
Bugzilla
CVE-2020-6388 chromium-browser: Out of bounds memory access in WebAudio
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6388 [HIGH] CVE-2020-6388 chromium-browser: Out of bounds memory access in WebAudio
CVE-2020-6388 chromium-browser: Out of bounds memory access in WebAudio
An out of bounds memory access flaw was found in the WebAudio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1042879
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/
Bugzilla
CVE-2020-6402 chromium-browser: Insufficient policy enforcement in downloads
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6402 [HIGH] CVE-2020-6402 chromium-browser: Insufficient policy enforcement in downloads
CVE-2020-6402 chromium-browser: Insufficient policy enforcement in downloads
An insufficient policy enforcement flaw was found in the downloads component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1029375
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com
Bugzilla
CVE-2020-6417 chromium-browser: Inappropriate implementation in installer
bugzilla·2020-02-10·CVSS 7.8
CVE-2020-6417 [HIGH] CVE-2020-6417 chromium-browser: Inappropriate implementation in installer
CVE-2020-6417 chromium-browser: Inappropriate implementation in installer
An inappropriate implementation flaw was found in the installer component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1033824
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secur
Bugzilla
CVE-2020-6404 chromium-browser: Inappropriate implementation in Blink
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6404 [HIGH] CVE-2020-6404 chromium-browser: Inappropriate implementation in Blink
CVE-2020-6404 chromium-browser: Inappropriate implementation in Blink
An inappropriate implementation flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1024256
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/
Bugzilla
CVE-2020-6401 chromium-browser: Insufficient validation of untrusted input in Omnibox
bugzilla·2020-02-10·CVSS 6.5
CVE-2020-6401 [MEDIUM] CVE-2020-6401 chromium-browser: Insufficient validation of untrusted input in Omnibox
CVE-2020-6401 chromium-browser: Insufficient validation of untrusted input in Omnibox
An insufficient validation of untrusted input flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1017707
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https:/
Bugzilla
CVE-2020-6410 chromium-browser: Insufficient policy enforcement in navigation
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6410 [HIGH] CVE-2020-6410 chromium-browser: Insufficient policy enforcement in navigation
CVE-2020-6410 chromium-browser: Insufficient policy enforcement in navigation
An insufficient policy enforcement flaw was found in the navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=881675
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.co
Bugzilla
CVE-2020-6390 chromium-browser: Out of bounds memory access in streams
bugzilla·2020-02-10·CVSS 8.8
CVE-2020-6390 [HIGH] CVE-2020-6390 chromium-browser: Out of bounds memory access in streams
CVE-2020-6390 chromium-browser: Out of bounds memory access in streams
An out of bounds memory access flaw was found in the streams component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1045874
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1801839]
Affects: fedora-all [bug 1801838]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHSA-2020:0514
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cv
Bugzilla
CVE-2019-19925 sqlite: zipfileUpdate in ext/misc/zipfile.c mishandles a NULL pathname during an update of a ZIP archive
bugzilla·2020-01-08·CVSS 7.5
CVE-2019-19925 [HIGH] CVE-2019-19925 sqlite: zipfileUpdate in ext/misc/zipfile.c mishandles a NULL pathname during an update of a ZIP archive
CVE-2019-19925 sqlite: zipfileUpdate in ext/misc/zipfile.c mishandles a NULL pathname during an update of a ZIP archive
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
Upstream Fix:
https://github.com/sqlite/sqlite/commit/54d501092d88c0cf89bec4279951f548fb0b8618
Discussion:
Created sqlite tracking bugs for this issue:
Affects: fedora-30 [bug 1788867]
---
Created sqlite tracking bugs for this issue:
Affects: fedora-31 [bug 1789800]
---
Statement:
The zip extension was introduced in sqlite-3.22.0, therefore previous versions are not affected by this flaw.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.com/errata/RHS
Bugzilla
CVE-2019-19923 sqlite: mishandling of certain uses of SELECT DISTINCT involving a LEFT JOIN in flattenSubquery in select.c leads to a NULL pointer dereference
bugzilla·2020-01-08·CVSS 7.5
CVE-2019-19923 [HIGH] CVE-2019-19923 sqlite: mishandling of certain uses of SELECT DISTINCT involving a LEFT JOIN in flattenSubquery in select.c leads to a NULL pointer dereference
CVE-2019-19923 sqlite: mishandling of certain uses of SELECT DISTINCT involving a LEFT JOIN in flattenSubquery in select.c leads to a NULL pointer dereference
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
Upstream fix:
https://github.com/sqlite/sqlite/commit/396afe6f6aa90a31303c183e11b2b2d4b7956b35
Discussion:
Created sqlite tracking bugs for this issue:
Affects: fedora-31 [bug 1788847]
---
Created sqlite tracking bugs for this issue:
Affects: fedora-30 [bug 1789799]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0514 https://access.redhat.co
2020-03-12
Published