CVE-2020-6514Sensitive Information Exposure in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
14.5%
top 5.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 24

Description

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages12 packages

CVEListV5google/chromeunspecified84.0.4147.89
NVDgoogle/chrome< 84.0.4147.89
NVDapple/tvos< 13.4.8
NVDapple/ipados< 13.6
NVDapple/safari< 13.1.2

Also affects: Debian Linux 10.0, 9.0, Fedora 31, 32, Ubuntu Linux 16.04, 18.04, 20.04

🔴Vulnerability Details

6
GHSA
GHSA-7vv8-8vrw-6j74: Inappropriate implementation in WebRTC in Google Chrome prior to 842022-05-24
Project0
Exploiting Android Messengers with WebRTC: Part 2 - Project Zero2020-08-01
Project0
Exploiting Android Messengers with WebRTC: Part 3 - Project Zero2020-08-01
OSV
firefox vulnerabilities2020-07-29
CVEList
CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 842020-07-22

📋Vendor Advisories

13
Ubuntu
Firefox vulnerabilities2020-07-29
Apple
CVE-2020-6514: watchOS 6.2.82020-07-15
Apple
CVE-2020-6514: tvOS 13.4.82020-07-15
Apple
CVE-2020-6514: iOS 13.6 and iPadOS 13.62020-07-15
Apple
CVE-2020-6514: Safari 13.1.22020-07-15

💬Community

5
Bugzilla
CVE-2020-6514 chromium-browser: Inappropriate implementation in WebRTC2020-07-15
Bugzilla
CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [fedora-all]2020-07-15
Bugzilla
CVE-2020-6514 chromium: chromium-browser: Inappropriate implementation in WebRTC [epel-all]2020-07-15
Bugzilla
CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-2020-07-15
Bugzilla
CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514 CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519 CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-2020-07-15
CVE-2020-6514 — Sensitive Information Exposure | cvebase