CVE-2020-6514
published 2020-07-22CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap…
PriorityP339medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
7.79%
94.0th percentile
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_13.6_and_ipados | — | — |
| apple | ipados | < 13.6 | 13.6 |
| apple | iphone_os | < 13.6 | 13.6 |
| apple | safari | < 13.1.2 | 13.1.2 |
| apple | safari | — | — |
| apple | tvos | < 13.4.8 | 13.4.8 |
| apple | tvos | — | — |
| apple | watchos | < 6.2.8 | 6.2.8 |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.88-0.1 | 87.0.4280.88-0.1 |
| debian | chromium | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| debian | firefox-esr | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| debian | thunderbird | < chromium 87.0.4280.88-0.1 (bookworm) | chromium 87.0.4280.88-0.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 84.0.4147.89 | 84.0.4147.89 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2020-07-29·CVSS 6.5
CVE-2020-15652 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass iframe sandbox restrictions, confuse the user, or
execute arbitrary code. (CVE-2020-6463, CVE-2020-6514, CVE-2020-15652,
CVE-2020-15653, CVE-2020-15654, CVE-2020-15656, CVE-2020-15658,
CVE-2020-15659)
It was discovered that redirected HTTP requests which are observed or
modified through a web extension could bypass existing CORS checks. If a
user were tricked in to installing a specially crafted extension, an
attacker could pote
Apple
CVE-2020-6514: watchOS 6.2.8
vendor_apple·2020-07-15·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514: watchOS 6.2.8
Apple Security Update: About the security content of watchOS 6.2.8
Product: watchOS
Version: 6.2.8
CVE: CVE-2020-6514
Component: WebRTC
Impact: An attacker in a privileged network position may be able to cause heap corruption via a crafted SCTP stream
Description: A memory corruption issue was addressed with improved state management.
Apple
CVE-2020-6514: tvOS 13.4.8
vendor_apple·2020-07-15·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514: tvOS 13.4.8
Apple Security Update: About the security content of tvOS 13.4.8
Product: tvOS
Version: 13.4.8
CVE: CVE-2020-6514
Component: WebRTC
Impact: An attacker in a privileged network position may be able to cause heap corruption via a crafted SCTP stream
Description: A memory corruption issue was addressed with improved state management.
Apple
CVE-2020-6514: iOS 13.6 and iPadOS 13.6
vendor_apple·2020-07-15·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-6514
Component: WebRTC
Impact: An attacker in a privileged network position may be able to cause heap corruption via a crafted SCTP stream
Description: A memory corruption issue was addressed with improved state management.
Apple
CVE-2020-6514: Safari 13.1.2
vendor_apple·2020-07-15·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514: Safari 13.1.2
Apple Security Update: About the security content of Safari 13.1.2
Product: Safari
Version: 13.1.2
CVE: CVE-2020-6514
Component: WebRTC
Impact: An attacker in a privileged network position may be able to cause heap corruption via a crafted SCTP stream
Description: A memory corruption issue was addressed with improved state management.
Chrome
Stable Channel Update for Desktop: CVE-2020-6514
vendor_chrome·2020-07-14·CVSS 6.5
CVE-2020-6514 [HIGH] Stable Channel Update for Desktop: CVE-2020-6514
Stable Channel Update for Desktop
CVE-2020-6514: Inappropriate implementation in WebRTC. Reported by Natalie Silvanovich of Google Project Zero on 2020-04-30
[$TBD][ 1082755 ] High CVE-2020-6515: Use after free in tab strip
Reported by DDV_UA on 2020-05-14
Severity: high
Red Hat
chromium-browser: Inappropriate implementation in WebRTC
vendor_redhat·2020-07-14·CVSS 6.5
CVE-2020-6514 [MEDIUM] chromium-browser: Inappropriate implementation in WebRTC
chromium-browser: Inappropriate implementation in WebRTC
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2020-6514: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 al...
vendor_debian·2020·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 al...
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixed in 87.0.4280.88-0.1)
Mozilla
Mozilla Foundation Security Advisory 2020-31: CVE-2020-6514
vendor_mozilla·CVSS 6.5
CVE-2020-6514 [MEDIUM] Mozilla Foundation Security Advisory 2020-31: CVE-2020-6514
Mozilla Foundation Security Advisory 2020-31
CVE: CVE-2020-6514
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.11
Mozilla
Mozilla Foundation Security Advisory 2020-32: CVE-2020-6514
vendor_mozilla·CVSS 6.5
CVE-2020-6514 [MEDIUM] Mozilla Foundation Security Advisory 2020-32: CVE-2020-6514
Mozilla Foundation Security Advisory 2020-32
CVE: CVE-2020-6514
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.1
Mozilla
Mozilla Foundation Security Advisory 2020-35: CVE-2020-6514
vendor_mozilla·CVSS 6.5
CVE-2020-6514 [MEDIUM] Mozilla Foundation Security Advisory 2020-35: CVE-2020-6514
Mozilla Foundation Security Advisory 2020-35
CVE: CVE-2020-6514
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 68.11
Mozilla
Mozilla Foundation Security Advisory 2020-30: CVE-2020-6514
vendor_mozilla·CVSS 6.5
CVE-2020-6514 [MEDIUM] Mozilla Foundation Security Advisory 2020-30: CVE-2020-6514
Mozilla Foundation Security Advisory 2020-30
CVE: CVE-2020-6514
Product: Firefox
Impact: high
Fixed in: Firefox 79
Mozilla
Mozilla Foundation Security Advisory 2020-33: CVE-2020-6514
vendor_mozilla·CVSS 6.5
CVE-2020-6514 [MEDIUM] Mozilla Foundation Security Advisory 2020-33: CVE-2020-6514
Mozilla Foundation Security Advisory 2020-33
CVE: CVE-2020-6514
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.1
GHSA
GHSA-7vv8-8vrw-6j74: Inappropriate implementation in WebRTC in Google Chrome prior to 84
ghsa_unreviewed·2022-05-24
CVE-2020-6514 [MEDIUM] GHSA-7vv8-8vrw-6j74: Inappropriate implementation in WebRTC in Google Chrome prior to 84
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Project0
Exploiting Android Messengers with WebRTC: Part 2 - Project Zero
project_zero·2020-08-01·CVSS 9.8
CVE-2020-6514 [CRITICAL] Exploiting Android Messengers with WebRTC: Part 2 - Project Zero
##
Posted by Natalie Silvanovich, Project Zero
This is a three-part series on exploiting messenger applications using vulnerabilities in WebRTC. This series highlights what can go wrong when applications don't apply WebRTC patches and when the communication and notification of security issues breaks down. Part 3 is scheduled for August 6.
##
Part 2: A Better Bug
In Part 1, I explored whether it was possible to exploit WebRTC using two memory corruption bugs in RTP processing. While I succeeded at moving the instruction pointer, I was not able to break ASLR, so I decided to look for vulnerabilities more suitable for this purpose.
##
usrsctp
I started off by going through WebRTC bugs I had filed in the past to see if any had the potential to break ASLR. Even if a bug was fixed long
Project0
Exploiting Android Messengers with WebRTC: Part 3 - Project Zero
project_zero·2020-08-01·CVSS 6.5
CVE-2020-6514 [MEDIUM] Exploiting Android Messengers with WebRTC: Part 3 - Project Zero
##
Posted by Natalie Silvanovich, Project Zero
This is a three-part series on exploiting messenger applications using vulnerabilities in WebRTC. CVE-2020-6514 discussed in the blog post was fixed on July 14 with these CLs.This series highlights what can go wrong when applications don't apply WebRTC patches and when the communication and notification of security issues breaks down.
##
Part 3: Which Messengers?
In Part 2, I described an exploit for WebRTC on Android. In this section, I explore which applications it works on.
##
The exploit
When writing the exploit, I originally altered the SCTP packets sent to the target device by altering the source of WebRTC and recompiling it. This wasn’t practical for attacking closed source applications, so I eventually switched to using Frida to
OSV
firefox vulnerabilities
osv·2020-07-29·CVSS 6.5
CVE-2020-6463 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass iframe sandbox restrictions, confuse the user, or
execute arbitrary code. (CVE-2020-6463, CVE-2020-6514, CVE-2020-15652,
CVE-2020-15653, CVE-2020-15654, CVE-2020-15656, CVE-2020-15658,
CVE-2020-15659)
It was discovered that redirected HTTP requests which are observed or
modified through a web extension could bypass existing CORS checks. If a
user were tricked in to installing a specially crafted extension, an
attacker could potentially exploit this to obtain sensitive information
across origins. (CVE-2020-15655)
OSV
CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84
osv·2020-07-22·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6514 chromium-browser: Inappropriate implementation in WebRTC
bugzilla·2020-07-15·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514 chromium-browser: Inappropriate implementation in WebRTC
CVE-2020-6514 chromium-browser: Inappropriate implementation in WebRTC
An inappropriate implementation flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1076703
External References:
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1857356]
Affects: fedora-all [bug 1857355]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
Via RHSA-2020:3229 https://access.redhat.com/errata/RHSA-2020:3229
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2020:3233 https://acc
Bugzilla
CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [fedora-all]
bugzilla·2020-07-15·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [fedora-all]
CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [epel-all]
bugzilla·2020-07-15·CVSS 6.5
CVE-2020-6514 [MEDIUM] CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [epel-all]
CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-
bugzilla·2020-07-15·CVSS 7.8
CVE-2020-6510 [HIGH] CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-
CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-2020-6524 ... chromium: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant t
Bugzilla
CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-
bugzilla·2020-07-15·CVSS 7.8
CVE-2020-6510 [HIGH] CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-
CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-2020-6524 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the releva
Bugzilla
WebRTC data channel leaks internal address to peer
bugzilla·2020-06-02
WebRTC data channel leaks internal address to peer
WebRTC data channel leaks internal address to peer
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
Steps to reproduce:
This was originally reported for Chrome here: https://bugs.chromium.org/p/chromium/issues/detail?id=1076703
But I looked at Firefox's code and found it was doing the same thing.
Quoted from the original reporter:
"When usrsctp is used with a custom transport, an address must be provided to usrsctp_conninput be used as the source and destination address of the incoming packet. WebRTC uses the address of the SctpTransport instance for this value. Unfortunately, this value is often transmitted to the peer, for example to validate signing of the cookie. This could allow an attacker acces
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00041.htmlhttp://packetstormsecurity.com/files/158697/WebRTC-usrsctp-Incorrect-Call.htmlhttps://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/1076703https://lists.debian.org/debian-lts-announce/2020/07/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTRPPTKZ2RKVH2XGQCWNFZ7FOGQ5LLCA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYIDWCHG24ZTFD4P42D4A4WWPPA74BCG/https://security.gentoo.org/glsa/202007-08https://security.gentoo.org/glsa/202007-64https://security.gentoo.org/glsa/202101-30https://support.apple.com/kb/HT211288https://support.apple.com/kb/HT211290https://support.apple.com/kb/HT211291https://support.apple.com/kb/HT211292https://usn.ubuntu.com/4443-1/https://www.debian.org/security/2020/dsa-4736https://www.debian.org/security/2020/dsa-4740https://www.debian.org/security/2021/dsa-4824http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00041.htmlhttp://packetstormsecurity.com/files/158697/WebRTC-usrsctp-Incorrect-Call.htmlhttps://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/1076703https://lists.debian.org/debian-lts-announce/2020/07/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTRPPTKZ2RKVH2XGQCWNFZ7FOGQ5LLCA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYIDWCHG24ZTFD4P42D4A4WWPPA74BCG/https://security.gentoo.org/glsa/202007-08https://security.gentoo.org/glsa/202007-64https://security.gentoo.org/glsa/202101-30https://support.apple.com/kb/HT211288https://support.apple.com/kb/HT211290https://support.apple.com/kb/HT211291https://support.apple.com/kb/HT211292https://usn.ubuntu.com/4443-1/https://www.debian.org/security/2020/dsa-4736https://www.debian.org/security/2020/dsa-4740https://www.debian.org/security/2021/dsa-4824
2020-07-22
Published