CVE-2020-6463
published 2020-05-21CVE-2020-6463: Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.89%
85.3th percentile
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| chromium | chromium | >= 0 < 83.0.4103.83-1 | 83.0.4103.83-1 |
| debian | chromium | < chromium 83.0.4103.83-1 (bookworm) | chromium 83.0.4103.83-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < chromium 83.0.4103.83-1 (bookworm) | chromium 83.0.4103.83-1 (bookworm) |
| debian | firefox-esr | < chromium 83.0.4103.83-1 (bookworm) | chromium 83.0.4103.83-1 (bookworm) |
| debian | thunderbird | < chromium 83.0.4103.83-1 (bookworm) | chromium 83.0.4103.83-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 81.0.4044.122 | 81.0.4044.122 | |
| chrome | >= unspecified < 81.0.4044.122 | 81.0.4044.122 | |
| chrome_chrome | — | — | |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 79.0+build1-0ubuntu0.16.04.2 | 79.0+build1-0ubuntu0.16.04.2 |
| mozilla | firefox | >= 0 < 79.0+build1-0ubuntu0.18.04.1 | 79.0+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 79.0+build1-0ubuntu0.20.04.1 | 79.0+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:68.11.0-1 | 1:68.11.0-1 |
| mozilla | thunderbird | >= 0 < 1:68.11.0-1 | 1:68.11.0-1 |
| mozilla | thunderbird | >= 0 < 1:68.11.0-1 | 1:68.11.0-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2020-07-29·CVSS 6.5
CVE-2020-15652 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass iframe sandbox restrictions, confuse the user, or
execute arbitrary code. (CVE-2020-6463, CVE-2020-6514, CVE-2020-15652,
CVE-2020-15653, CVE-2020-15654, CVE-2020-15656, CVE-2020-15658,
CVE-2020-15659)
It was discovered that redirected HTTP requests which are observed or
modified through a web extension could bypass existing CORS checks. If a
user were tricked in to installing a specially crafted extension, an
attacker could pote
Chrome
Stable Channel Update for Desktop: CVE-2020-6463
vendor_chrome·2020-04-21·CVSS 8.8
CVE-2020-6463 [HIGH] Stable Channel Update for Desktop: CVE-2020-6463
Stable Channel Update for Desktop
CVE-2020-6463: Use after free in ANGLE. Reported by Pawel Wylecial of REDTEAM
Severity: high
Red Hat
chromium-browser: Use after free in ANGLE
vendor_redhat·2020-04-21·CVSS 8.8
CVE-2020-6463 [HIGH] CWE-416 chromium-browser: Use after free in ANGLE
chromium-browser: Use after free in ANGLE
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2020-6463: chromium - Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote...
vendor_debian·2020·CVSS 8.8
CVE-2020-6463 [HIGH] CVE-2020-6463: chromium - Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote...
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.0.4103.83-1)
Mozilla
Mozilla Foundation Security Advisory 2020-33: CVE-2020-6463
vendor_mozilla·CVSS 8.8
CVE-2020-6463 [HIGH] Mozilla Foundation Security Advisory 2020-33: CVE-2020-6463
Mozilla Foundation Security Advisory 2020-33
CVE: CVE-2020-6463
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.1
Mozilla
Mozilla Foundation Security Advisory 2020-32: CVE-2020-6463
vendor_mozilla·CVSS 8.8
CVE-2020-6463 [HIGH] Mozilla Foundation Security Advisory 2020-32: CVE-2020-6463
Mozilla Foundation Security Advisory 2020-32
CVE: CVE-2020-6463
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.1
Mozilla
Mozilla Foundation Security Advisory 2020-31: CVE-2020-6463
vendor_mozilla·CVSS 8.8
CVE-2020-6463 [HIGH] Mozilla Foundation Security Advisory 2020-31: CVE-2020-6463
Mozilla Foundation Security Advisory 2020-31
CVE: CVE-2020-6463
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.11
Mozilla
Mozilla Foundation Security Advisory 2020-30: CVE-2020-6463
vendor_mozilla·CVSS 8.8
CVE-2020-6463 [HIGH] Mozilla Foundation Security Advisory 2020-30: CVE-2020-6463
Mozilla Foundation Security Advisory 2020-30
CVE: CVE-2020-6463
Product: Firefox
Impact: high
Fixed in: Firefox 79
Mozilla
Mozilla Foundation Security Advisory 2020-35: CVE-2020-6463
vendor_mozilla·CVSS 8.8
CVE-2020-6463 [HIGH] Mozilla Foundation Security Advisory 2020-35: CVE-2020-6463
Mozilla Foundation Security Advisory 2020-35
CVE: CVE-2020-6463
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 68.11
GHSA
GHSA-vmqg-547g-3f2r: Use after free in ANGLE in Google Chrome prior to 81
ghsa_unreviewed·2022-05-24
CVE-2020-6463 [MEDIUM] CWE-416 GHSA-vmqg-547g-3f2r: Use after free in ANGLE in Google Chrome prior to 81
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
firefox vulnerabilities
osv·2020-07-29·CVSS 6.5
CVE-2020-6463 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass iframe sandbox restrictions, confuse the user, or
execute arbitrary code. (CVE-2020-6463, CVE-2020-6514, CVE-2020-15652,
CVE-2020-15653, CVE-2020-15654, CVE-2020-15656, CVE-2020-15658,
CVE-2020-15659)
It was discovered that redirected HTTP requests which are observed or
modified through a web extension could bypass existing CORS checks. If a
user were tricked in to installing a specially crafted extension, an
attacker could potentially exploit this to obtain sensitive information
across origins. (CVE-2020-15655)
OSV
CVE-2020-6463: Use after free in ANGLE in Google Chrome prior to 81
osv·2020-05-21·CVSS 8.8
CVE-2020-6463 [HIGH] CVE-2020-6463: Use after free in ANGLE in Google Chrome prior to 81
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6463 chromium: chromium-browser: Use after free in ANGLE [epel-all]
bugzilla·2020-05-27·CVSS 8.8
CVE-2020-6463 [HIGH] CVE-2020-6463 chromium: chromium-browser: Use after free in ANGLE [epel-all]
CVE-2020-6463 chromium: chromium-browser: Use after free in ANGLE [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2020-6463 chromium-browser: Use after free in ANGLE
bugzilla·2020-05-27·CVSS 8.8
CVE-2020-6463 [HIGH] CVE-2020-6463 chromium-browser: Use after free in ANGLE
CVE-2020-6463 chromium-browser: Use after free in ANGLE
An use after free flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1065186
External References:
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1840897]
Affects: fedora-all [bug 1840896]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1970 https://access.redhat.com/errata/RHSA-2020:1970
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
Via RHSA-2020:3229 https://access.redhat.co
Bugzilla
CVE-2020-6463 chromium: chromium-browser: Use after free in ANGLE [fedora-all]
bugzilla·2020-05-27·CVSS 8.8
CVE-2020-6463 [HIGH] CVE-2020-6463 chromium: chromium-browser: Use after free in ANGLE [fedora-all]
CVE-2020-6463 chromium: chromium-browser: Use after free in ANGLE [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
UAF in ANGLE gl::Texture::onUnbindAsSamplerTexture
bugzilla·2020-05-04·CVSS 8.8
[HIGH] UAF in ANGLE gl::Texture::onUnbindAsSamplerTexture
UAF in ANGLE gl::Texture::onUnbindAsSamplerTexture
The Chrome team has taken a fix from ANGLE to patch a UAF. The patch applies to our source and isn't is one the parts I know we don't use so it probably affects Firefox, too. "Reported by Pawel Wylecial of REDTEAM.PL on 2020-03-26" according to their stable release notes.
Chrome bug (hidden): https://bugs.chromium.org/p/chromium/issues/detail?id=1065186
Patch:
https://chromium.googlesource.com/angle/angle/+/91c39dae9a518706f2635ac8b87f9f5b5ed9001c
Chrome has assigned CVE-2020-6463
[reference: https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html]
Discussion:
Rating based on chrome bug assuming it affects Firefox too.
---
AFAICT that code hasn't changed in awhile and affects all supported branches.
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00032.htmlhttps://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.htmlhttps://crbug.com/1065186https://lists.debian.org/debian-lts-announce/2020/07/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQYH5OK7O4BU6E37WWG5SEEHV65BFSGR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLFZ5N4EK6I4ZJP5YSKLLVN3ELXEB4XT/https://security.gentoo.org/glsa/202007-60https://security.gentoo.org/glsa/202007-64https://usn.ubuntu.com/4443-1/https://www.debian.org/security/2020/dsa-4714https://www.debian.org/security/2020/dsa-4736https://www.debian.org/security/2020/dsa-4740http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00032.htmlhttps://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.htmlhttps://crbug.com/1065186https://lists.debian.org/debian-lts-announce/2020/07/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQYH5OK7O4BU6E37WWG5SEEHV65BFSGR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLFZ5N4EK6I4ZJP5YSKLLVN3ELXEB4XT/https://security.gentoo.org/glsa/202007-60https://security.gentoo.org/glsa/202007-64https://usn.ubuntu.com/4443-1/https://www.debian.org/security/2020/dsa-4714https://www.debian.org/security/2020/dsa-4736https://www.debian.org/security/2020/dsa-4740
2020-05-21
Published