CVE-2020-1487
published 2020-08-17CVE-2020-1487: An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this…
PriorityP334medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
3.57%
88.1th percentile
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log onto an affected system and open a specially crafted file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file.
The update addresses the vulnerability by correcting how Media Foundation handles objects in memory.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Media Foundation Information Disclosure Vulnerability
vendor_msrc·2020-08-11·CVSS 5.5
CVE-2020-1487 [HIGH] Media Foundation Information Disclosure Vulnerability
Media Foundation Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log onto an affected system and open a specially crafted file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, t
GHSA
GHSA-gf86-frf5-frmh: An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosur
ghsa_unreviewed·2022-05-24
CVE-2020-1487 [MEDIUM] CWE-200 GHSA-gf86-frf5-frmh: An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosur
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6448 chromium-browser: Use after free in V8
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6448 [HIGH] CVE-2020-6448 chromium-browser: Use after free in V8
CVE-2020-6448 chromium-browser: Use after free in V8
An use after free flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1037872
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6448
Bugzilla
CVE-2020-6446 chromium-browser: Insufficient policy enforcement in trusted types
bugzilla·2020-04-09·CVSS 6.5
CVE-2020-6446 [MEDIUM] CVE-2020-6446 chromium-browser: Insufficient policy enforcement in trusted types
CVE-2020-6446 chromium-browser: Insufficient policy enforcement in trusted types
An insufficient policy enforcement flaw was found in the trusted types component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=933172
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access
Bugzilla
CVE-2020-6440 chromium-browser: Inappropriate implementation in extensions
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6440 [MEDIUM] CVE-2020-6440 chromium-browser: Inappropriate implementation in extensions
CVE-2020-6440 chromium-browser: Inappropriate implementation in extensions
An inappropriate implementation flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=894477
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
Bugzilla
CVE-2020-6439 chromium-browser: Insufficient policy enforcement in navigations
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6439 [HIGH] CVE-2020-6439 chromium-browser: Insufficient policy enforcement in navigations
CVE-2020-6439 chromium-browser: Insufficient policy enforcement in navigations
An insufficient policy enforcement flaw was found in the navigations component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=868145
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.red
Bugzilla
CVE-2020-6441 chromium-browser: Insufficient policy enforcement in omnibox
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6441 [MEDIUM] CVE-2020-6441 chromium-browser: Insufficient policy enforcement in omnibox
CVE-2020-6441 chromium-browser: Insufficient policy enforcement in omnibox
An insufficient policy enforcement flaw was found in the omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=959571
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
Bugzilla
CVE-2020-6456 chromium-browser: Insufficient validation of untrusted input in clipboard
bugzilla·2020-04-09·CVSS 6.5
CVE-2020-6456 [MEDIUM] CVE-2020-6456 chromium-browser: Insufficient validation of untrusted input in clipboard
CVE-2020-6456 chromium-browser: Insufficient validation of untrusted input in clipboard
An insufficient validation of untrusted input flaw was found in the clipboard component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1040755
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
Bugzilla
CVE-2020-6455 chromium-browser: Out of bounds read in WebSQL
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6455 [HIGH] CVE-2020-6455 chromium-browser: Out of bounds read in WebSQL
CVE-2020-6455 chromium-browser: Out of bounds read in WebSQL
An out of bounds read flaw was found in the WebSQL component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1059669
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6455
Bugzilla
CVE-2020-6443 chromium-browser: Insufficient data validation in developer tools
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6443 [HIGH] CVE-2020-6443 chromium-browser: Insufficient data validation in developer tools
CVE-2020-6443 chromium-browser: Insufficient data validation in developer tools
An insufficient data validation flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1040080
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.
Bugzilla
CVE-2020-6432 chromium-browser: Insufficient policy enforcement in navigations
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6432 [MEDIUM] CVE-2020-6432 chromium-browser: Insufficient policy enforcement in navigations
CVE-2020-6432 chromium-browser: Insufficient policy enforcement in navigations
An insufficient policy enforcement flaw was found in the navigations component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=965611
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.red
Bugzilla
CVE-2020-6435 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6435 [MEDIUM] CVE-2020-6435 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-6435 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1032158
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
Bugzilla
CVE-2020-6433 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6433 [MEDIUM] CVE-2020-6433 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-6433 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1043965
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
Bugzilla
CVE-2020-6431 chromium-browser: Insufficient policy enforcement in full screen
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6431 [MEDIUM] CVE-2020-6431 chromium-browser: Insufficient policy enforcement in full screen
CVE-2020-6431 chromium-browser: Insufficient policy enforcement in full screen
An insufficient policy enforcement flaw was found in the full screen component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=852645
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.red
Bugzilla
CVE-2020-6434 chromium-browser: Use after free in devtools
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6434 [HIGH] CVE-2020-6434 chromium-browser: Use after free in devtools
CVE-2020-6434 chromium-browser: Use after free in devtools
An use after free flaw was found in the devtools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1048555
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6434
Bugzilla
CVE-2020-6436 chromium-browser: Use after free in window management
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6436 [HIGH] CVE-2020-6436 chromium-browser: Use after free in window management
CVE-2020-6436 chromium-browser: Use after free in window management
An use after free flaw was found in the window management component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1034519
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/
Bugzilla
CVE-2020-6438 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6438 [MEDIUM] CVE-2020-6438 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-6438 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=714617
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-6423 chromium-browser: Use after free in audio
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6423 [HIGH] CVE-2020-6423 chromium-browser: Use after free in audio
CVE-2020-6423 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1043446
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6423
Bugzilla
CVE-2020-6442 chromium-browser: Inappropriate implementation in cache
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6442 [MEDIUM] CVE-2020-6442 chromium-browser: Inappropriate implementation in cache
CVE-2020-6442 chromium-browser: Inappropriate implementation in cache
An inappropriate implementation flaw was found in the cache component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1013906
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/
Bugzilla
CVE-2020-6430 chromium-browser: Type Confusion in V8
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6430 [HIGH] CVE-2020-6430 chromium-browser: Type Confusion in V8
CVE-2020-6430 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1031479
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6430
Bugzilla
CVE-2020-6437 chromium-browser: Inappropriate implementation in WebView
bugzilla·2020-04-09·CVSS 4.3
CVE-2020-6437 [MEDIUM] CVE-2020-6437 chromium-browser: Inappropriate implementation in WebView
CVE-2020-6437 chromium-browser: Inappropriate implementation in WebView
An inappropriate implementation flaw was found in the WebView component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=639173
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securi
Bugzilla
CVE-2020-6447 chromium-browser: Inappropriate implementation in developer tools
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6447 [HIGH] CVE-2020-6447 chromium-browser: Inappropriate implementation in developer tools
CVE-2020-6447 chromium-browser: Inappropriate implementation in developer tools
An inappropriate implementation flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=991217
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.r
Bugzilla
CVE-2020-6444 chromium-browser: Uninitialized use in WebRTC
bugzilla·2020-04-09·CVSS 6.3
CVE-2020-6444 [MEDIUM] CVE-2020-6444 chromium-browser: Uninitialized use in WebRTC
CVE-2020-6444 chromium-browser: Uninitialized use in WebRTC
An uninitialized use flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=922882
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6444
Bugzilla
CVE-2020-6445 chromium-browser: Insufficient policy enforcement in trusted types
bugzilla·2020-04-09·CVSS 6.5
CVE-2020-6445 [MEDIUM] CVE-2020-6445 chromium-browser: Insufficient policy enforcement in trusted types
CVE-2020-6445 chromium-browser: Insufficient policy enforcement in trusted types
An insufficient policy enforcement flaw was found in the trusted types component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=933171
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access
Bugzilla
CVE-2020-6454 chromium-browser: Use after free in extensions
bugzilla·2020-04-09·CVSS 8.8
CVE-2020-6454 [HIGH] CVE-2020-6454 chromium-browser: Use after free in extensions
CVE-2020-6454 chromium-browser: Use after free in extensions
An use after free flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1019161
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1822628]
Affects: fedora-all [bug 1822627]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1487 https://access.redhat.com/errata/RHSA-2020:1487
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6454
2020-08-17
Published