CVE-2020-6407
published 2020-02-27CVE-2020-6407: Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.78%
76.0th percentile
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 80.0.3987.122-1 | 80.0.3987.122-1 |
| chromium | chromium | >= 0 < 80.0.3987.122-1 | 80.0.3987.122-1 |
| chromium | chromium | >= 0 < 80.0.3987.122-1 | 80.0.3987.122-1 |
| chromium | chromium | >= 0 < 80.0.3987.122-1 | 80.0.3987.122-1 |
| debian | chromium | < chromium 80.0.3987.122-1 (bookworm) | chromium 80.0.3987.122-1 (bookworm) |
| chrome | < 80.0.3987.122 | 80.0.3987.122 | |
| chrome | >= unspecified < 80.0.3987.122 | 80.0.3987.122 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Out of bounds memory access in streams
vendor_redhat·2020-02-26·CVSS 8.8
CVE-2020-6407 [HIGH] chromium-browser: Out of bounds memory access in streams
chromium-browser: Out of bounds memory access in streams
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Chrome
Stable Channel Update for Desktop: CVE-2020-6407
vendor_chrome·2020-02-24·CVSS 8.8
CVE-2020-6407 [HIGH] Stable Channel Update for Desktop: CVE-2020-6407
Stable Channel Update for Desktop
CVE-2020-6407: Out of bounds memory access in streams. Reported by Sergei Glazunov of Google Project Zero on 2020-01-27
This release also contains:
[N/A][ 1053604 ] High CVE-2020-6418: Type confusion in V8
Reported by Clement Lecigne of Google's Threat Analysis Group on 2020-02-18
Severity: high
Debian
CVE-2020-6407: chromium - Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 a...
vendor_debian·2020·CVSS 8.8
CVE-2020-6407 [HIGH] CVE-2020-6407: chromium - Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 a...
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.122-1)
bullseye: resolved (fixed in 80.0.3987.122-1)
forky: resolved (fixed in 80.0.3987.122-1)
sid: resolved (fixed in 80.0.3987.122-1)
trixie: resolved (fixed in 80.0.3987.122-1)
GHSA
GHSA-cjhv-77fv-j3wp: Out of bounds memory access in streams in Google Chrome prior to 80
ghsa_unreviewed·2022-05-24
CVE-2020-6407 [MEDIUM] GHSA-cjhv-77fv-j3wp: Out of bounds memory access in streams in Google Chrome prior to 80
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2020-6407: Out of bounds memory access in streams in Google Chrome prior to 80
osv·2020-02-27·CVSS 8.8
CVE-2020-6407 [HIGH] CVE-2020-6407: Out of bounds memory access in streams in Google Chrome prior to 80
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6407 chromium-browser: Out of bounds memory access in streams
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6407 [HIGH] CVE-2020-6407 chromium-browser: Out of bounds memory access in streams
CVE-2020-6407 chromium-browser: Out of bounds memory access in streams
Out of bounds memory access in streams.
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807383]
Affects: fedora-all [bug 1807382]
---
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
---
*** Bug 1807341 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0738 https://access.redhat.com/errata/RHSA-2020:0738
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6407
Bugzilla
chromium: chromium-browser: Out of bounds memory access in streams [fedora-all]
bugzilla·2020-02-26
[HIGH] chromium: chromium-browser: Out of bounds memory access in streams [fedora-all]
chromium: chromium-browser: Out of bounds memory access in streams [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
chromium-browser: Out of bounds memory access in streams
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6407 [HIGH] chromium-browser: Out of bounds memory access in streams
chromium-browser: Out of bounds memory access in streams
Out of bounds memory access in streams.
Discussion:
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
---
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807355]
Affects: fedora-all [bug 1807354]
---
I think the CVE was mis-typed. This should be CVE-2020-6407.
---
That would make it a duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=1807381
---
Right, I was just investigating this and also came to a conclusion that a typo was made when filing this bug and it's a dupe of CVE-2020-6407.
*** This bug has been marked as a duplicate of bug 1807381 ***
Bugzilla
chromium: chromium-browser: Out of bounds memory access in streams [epel-all]
bugzilla·2020-02-26
[HIGH] chromium: chromium-browser: Out of bounds memory access in streams [epel-all]
chromium: chromium-browser: Out of bounds memory access in streams [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2020-6407 chromium: chromium-browser: out of bounds memory access in streams [epel-all]
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6407 [HIGH] CVE-2020-6407 chromium: chromium-browser: out of bounds memory access in streams [epel-all]
CVE-2020-6407 chromium: chromium-browser: out of bounds memory access in streams [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2020-6407 chromium: chromium-browser: out of bounds memory access in streams [fedora-all]
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6407 [HIGH] CVE-2020-6407 chromium: chromium-browser: out of bounds memory access in streams [fedora-all]
CVE-2020-6407 chromium: chromium-browser: out of bounds memory access in streams [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Tenable
CVE-2020-6418: Google Chrome Type Confusion Vulnerability Exploited in the Wild
blogs_tenable·2020-02-24·CVSS 8.8
[HIGH] CVE-2020-6418: Google Chrome Type Confusion Vulnerability Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://access.redhat.com/errata/RHSA-2020:0738https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/1045931https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/https://security.gentoo.org/glsa/202003-08https://www.debian.org/security/2020/dsa-4638https://access.redhat.com/errata/RHSA-2020:0738https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/1045931https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/https://security.gentoo.org/glsa/202003-08https://www.debian.org/security/2020/dsa-4638
2020-02-27
Published