CVE-2020-3377
published 2020-07-31CVE-2020-3377: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.02%
59.3th percentile
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific field within the application. A successful exploit could allow the attacker to run commands as the administrator on the DCNM.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_data_center_network_manager | — | — |
| cisco | data_center_network_manager | — | — |
| cisco | data_center_network_manager | — | — |
| cisco | data_center_network_manager | — | — |
| cisco | data_center_network_manager | — | — |
| cisco | data_center_network_manager | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Data Center Network Manager Command Injection Vulnerability
vendor_cisco·2020-07-29·CVSS 6.3
CVE-2020-3377 [MEDIUM] CWE-78 Cisco Data Center Network Manager Command Injection Vulnerability
Cisco Data Center Network Manager Command Injection Vulnerability
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific field within the application. A successful exploit could allow the attacker to run commands as the administrator on the DCNM.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdv
Cisco
Cisco Data Center Network Manager Command Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3377 Cisco Data Center Network Manager Command Injection Vulnerability
CVE-2020-3377: Cisco Data Center Network Manager Command Injection Vulnerability
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific field within the application. A successful exploit could allow the attacker to run commands as the administrator on the DCNM. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-78, CWE-78
Bug IDs: CSCvt54521
GHSA
GHSA-cvp7-c3qw-m5fw: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject
ghsa_unreviewed·2022-05-24
CVE-2020-3377 [MEDIUM] GHSA-cvp7-c3qw-m5fw: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific field within the application. A successful exploit could allow the attacker to run commands as the administrator on the DCNM.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6540 chromium-browser: Heap buffer overflow in Skia
bugzilla·2020-07-28·CVSS 8.8
CVE-2020-6540 [HIGH] CVE-2020-6540 chromium-browser: Heap buffer overflow in Skia
CVE-2020-6540 chromium-browser: Heap buffer overflow in Skia
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1105720
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1861472]
Affects: fedora-all [bug 1861471]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6540
Bugzilla
CVE-2020-6541 chromium-browser: Use after free in WebUSB
bugzilla·2020-07-28·CVSS 8.8
CVE-2020-6541 [HIGH] CVE-2020-6541 chromium-browser: Use after free in WebUSB
CVE-2020-6541 chromium-browser: Use after free in WebUSB
An use after free flaw was found in the WebUSB component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1106773
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1861472]
Affects: fedora-all [bug 1861471]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6541
Bugzilla
CVE-2020-6538 chromium-browser: Inappropriate implementation in WebView
bugzilla·2020-07-28·CVSS 6.5
CVE-2020-6538 [MEDIUM] CVE-2020-6538 chromium-browser: Inappropriate implementation in WebView
CVE-2020-6538 chromium-browser: Inappropriate implementation in WebView
An inappropriate implementation flaw was found in the WebView component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1096677
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1861472]
Affects: fedora-all [bug 1861471]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secu
Bugzilla
CVE-2020-6537 chromium-browser: Type Confusion in V8
bugzilla·2020-07-28·CVSS 8.8
CVE-2020-6537 [HIGH] CVE-2020-6537 chromium-browser: Type Confusion in V8
CVE-2020-6537 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1105318
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1861472]
Affects: fedora-all [bug 1861471]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6537
Bugzilla
CVE-2020-6539 chromium-browser: Use after free in CSS
bugzilla·2020-07-28·CVSS 8.8
CVE-2020-6539 [HIGH] CVE-2020-6539 chromium-browser: Use after free in CSS
CVE-2020-6539 chromium-browser: Use after free in CSS
An use after free flaw was found in the CSS component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1105635
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1861472]
Affects: fedora-all [bug 1861471]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6539
Bugzilla
CVE-2020-6532 chromium-browser: Use after free in SCTP
bugzilla·2020-07-28·CVSS 8.8
CVE-2020-6532 [HIGH] CVE-2020-6532 chromium-browser: Use after free in SCTP
CVE-2020-6532 chromium-browser: Use after free in SCTP
An use after free flaw was found in the SCTP component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1104061
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1861472]
Affects: fedora-all [bug 1861471]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6532
Bugzilla
CVE-2020-6521 chromium-browser: Side-channel information leakage in autofill
bugzilla·2020-07-15·CVSS 6.5
CVE-2020-6521 [MEDIUM] CVE-2020-6521 chromium-browser: Side-channel information leakage in autofill
CVE-2020-6521 chromium-browser: Side-channel information leakage in autofill
A side-channel information leakage flaw was found in the autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1075734
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.co
Bugzilla
CVE-2020-6517 chromium-browser: Heap buffer overflow in history
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6517 [HIGH] CVE-2020-6517 chromium-browser: Heap buffer overflow in history
CVE-2020-6517 chromium-browser: Heap buffer overflow in history
A heap buffer overflow flaw was found in the history component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1095560
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6517
Bugzilla
CVE-2020-6512 chromium-browser: Type Confusion in V8
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6512 [HIGH] CVE-2020-6512 chromium-browser: Type Confusion in V8
CVE-2020-6512 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1084820
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6512
Bugzilla
CVE-2020-6520 chromium-browser: Heap buffer overflow in Skia
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6520 [HIGH] CVE-2020-6520 chromium-browser: Heap buffer overflow in Skia
CVE-2020-6520 chromium-browser: Heap buffer overflow in Skia
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1092274
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6520
Bugzilla
CVE-2020-6525 chromium-browser: Heap buffer overflow in Skia
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6525 [HIGH] CVE-2020-6525 chromium-browser: Heap buffer overflow in Skia
CVE-2020-6525 chromium-browser: Heap buffer overflow in Skia
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1091670
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6525
Bugzilla
CVE-2020-6533 chromium-browser: Type Confusion in V8
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6533 [HIGH] CVE-2020-6533 chromium-browser: Type Confusion in V8
CVE-2020-6533 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1069964
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6533
Bugzilla
CVE-2020-6529 chromium-browser: Inappropriate implementation in WebRTC
bugzilla·2020-07-15·CVSS 4.3
CVE-2020-6529 [MEDIUM] CVE-2020-6529 chromium-browser: Inappropriate implementation in WebRTC
CVE-2020-6529 chromium-browser: Inappropriate implementation in WebRTC
An inappropriate implementation flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=978779
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/c
Bugzilla
CVE-2020-6530 chromium-browser: Out of bounds memory access in developer tools
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6530 [HIGH] CVE-2020-6530 chromium-browser: Out of bounds memory access in developer tools
CVE-2020-6530 chromium-browser: Out of bounds memory access in developer tools
An out of bounds memory access flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1016278
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
Bugzilla
CVE-2020-6516 chromium-browser: Policy bypass in CORS
bugzilla·2020-07-15·CVSS 4.3
CVE-2020-6516 [MEDIUM] CVE-2020-6516 chromium-browser: Policy bypass in CORS
CVE-2020-6516 chromium-browser: Policy bypass in CORS
A policy bypass flaw was found in the CORS component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1092449
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6516
Bugzilla
CVE-2020-6536 chromium-browser: Incorrect security UI in PWAs
bugzilla·2020-07-15·CVSS 4.3
CVE-2020-6536 [MEDIUM] CVE-2020-6536 chromium-browser: Incorrect security UI in PWAs
CVE-2020-6536 chromium-browser: Incorrect security UI in PWAs
An incorrect security ui flaw was found in the PWAs component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1080934
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6536
Bugzilla
CVE-2020-6527 chromium-browser: Insufficient policy enforcement in CSP
bugzilla·2020-07-15·CVSS 4.3
CVE-2020-6527 [MEDIUM] CVE-2020-6527 chromium-browser: Insufficient policy enforcement in CSP
CVE-2020-6527 chromium-browser: Insufficient policy enforcement in CSP
An insufficient policy enforcement flaw was found in the CSP component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=992698
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/c
Bugzilla
CVE-2020-6531 chromium-browser: Side-channel information leakage in scroll to text
bugzilla·2020-07-15·CVSS 4.3
CVE-2020-6531 [MEDIUM] CVE-2020-6531 chromium-browser: Side-channel information leakage in scroll to text
CVE-2020-6531 chromium-browser: Side-channel information leakage in scroll to text
A side-channel information leakage flaw was found in the scroll to text component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1042986
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://acce
Bugzilla
CVE-2020-6519 chromium-browser: Policy bypass in CSP
bugzilla·2020-07-15·CVSS 6.5
CVE-2020-6519 [MEDIUM] CVE-2020-6519 chromium-browser: Policy bypass in CSP
CVE-2020-6519 chromium-browser: Policy bypass in CSP
A policy bypass flaw was found in the CSP component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1064676
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6519
Bugzilla
CVE-2020-6526 chromium-browser: Inappropriate implementation in iframe sandbox
bugzilla·2020-07-15·CVSS 6.5
CVE-2020-6526 [MEDIUM] CVE-2020-6526 chromium-browser: Inappropriate implementation in iframe sandbox
CVE-2020-6526 chromium-browser: Inappropriate implementation in iframe sandbox
An inappropriate implementation flaw was found in the iframe sandbox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1074340
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
Bugzilla
CVE-2020-6518 chromium-browser: Use after free in developer tools
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6518 [HIGH] CVE-2020-6518 chromium-browser: Use after free in developer tools
CVE-2020-6518 chromium-browser: Use after free in developer tools
An use after free flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=986051
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-202
Bugzilla
CVE-2020-6528 chromium-browser: Incorrect security UI in basic auth
bugzilla·2020-07-15·CVSS 4.3
CVE-2020-6528 [MEDIUM] CVE-2020-6528 chromium-browser: Incorrect security UI in basic auth
CVE-2020-6528 chromium-browser: Incorrect security UI in basic auth
An incorrect security ui flaw was found in the basic auth component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1063690
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cv
Bugzilla
CVE-2020-6524 chromium-browser: Heap buffer overflow in WebAudio
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6524 [HIGH] CVE-2020-6524 chromium-browser: Heap buffer overflow in WebAudio
CVE-2020-6524 chromium-browser: Heap buffer overflow in WebAudio
A heap buffer overflow flaw was found in the WebAudio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1081722
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-
Bugzilla
CVE-2020-6510 chromium-browser: Heap buffer overflow in background fetch
bugzilla·2020-07-15·CVSS 7.8
CVE-2020-6510 [HIGH] CVE-2020-6510 chromium-browser: Heap buffer overflow in background fetch
CVE-2020-6510 chromium-browser: Heap buffer overflow in background fetch
A heap buffer overflow flaw was found in the background fetch component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1103195
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857403]
Affects: fedora-all [bug 1857402]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securi
Bugzilla
CVE-2020-6511 chromium-browser: Side-channel information leakage in content security policy
bugzilla·2020-07-15·CVSS 6.5
CVE-2020-6511 [MEDIUM] CVE-2020-6511 chromium-browser: Side-channel information leakage in content security policy
CVE-2020-6511 chromium-browser: Side-channel information leakage in content security policy
A side-channel information leakage flaw was found in the content security policy component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1074317
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page
Bugzilla
CVE-2020-6522 chromium-browser: Inappropriate implementation in external protocol handlers
bugzilla·2020-07-15·CVSS 9.6
CVE-2020-6522 [CRITICAL] CVE-2020-6522 chromium-browser: Inappropriate implementation in external protocol handlers
CVE-2020-6522 chromium-browser: Inappropriate implementation in external protocol handlers
An inappropriate implementation flaw was found in the external protocol handlers component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1052093
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6522
Bugzilla
CVE-2020-6534 chromium-browser: Heap buffer overflow in WebRTC
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6534 [HIGH] CVE-2020-6534 chromium-browser: Heap buffer overflow in WebRTC
CVE-2020-6534 chromium-browser: Heap buffer overflow in WebRTC
A heap buffer overflow flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1072412
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6534
Bugzilla
CVE-2020-6515 chromium-browser: Use after free in tab strip
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6515 [HIGH] CVE-2020-6515 chromium-browser: Use after free in tab strip
CVE-2020-6515 chromium-browser: Use after free in tab strip
An use after free flaw was found in the tab strip component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1082755
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6515
Bugzilla
CVE-2020-6513 chromium-browser: Heap buffer overflow in PDFium
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6513 [HIGH] CVE-2020-6513 chromium-browser: Heap buffer overflow in PDFium
CVE-2020-6513 chromium-browser: Heap buffer overflow in PDFium
A heap buffer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1091404
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6513
Bugzilla
CVE-2020-6523 chromium-browser: Out of bounds write in Skia
bugzilla·2020-07-15·CVSS 8.8
CVE-2020-6523 [HIGH] CVE-2020-6523 chromium-browser: Out of bounds write in Skia
CVE-2020-6523 chromium-browser: Out of bounds write in Skia
An out of bounds write flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1080481
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6523
Bugzilla
CVE-2020-6535 chromium-browser: Insufficient data validation in WebUI
bugzilla·2020-07-15·CVSS 6.1
CVE-2020-6535 [MEDIUM] CVE-2020-6535 chromium-browser: Insufficient data validation in WebUI
CVE-2020-6535 chromium-browser: Insufficient data validation in WebUI
An insufficient data validation flaw was found in the WebUI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1073409
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857345]
Affects: fedora-all [bug 1857344]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3377 https://access.redhat.com/errata/RHSA-2020:3377
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cv
2020-07-31
Published