Lucene search

K
gentooGentoo FoundationGLSA-202008-10
HistoryAug 25, 2020 - 12:00 a.m.

Chromium, Google Chrome: Heap buffer overflow

2020-08-2500:00:00
Gentoo Foundation
security.gentoo.org
33
chromium
google chrome
swiftshader
buffer overflow
remote attacker
arbitrary code
upgrade
version
website.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.008

Percentile

82.0%

Background

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.

Google Chrome is one fast, simple, and secure browser for all your devices.

Description

A buffer overflow has been discovered in Chromium and Google Chrome’s SwiftShader component.

Impact

A remote attacker, by enticing a user to visit a specially crafted website, could execute arbitrary code with the privileges of the process.

Workaround

There is no known workaround at this time.

Resolution

All Chromium users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose
 ">=www-client/chromium-84.0.4147.135"

All Google Chrome users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose
 ">=www-client/google-chrome-84.0.4147.135"
OSVersionArchitecturePackageVersionFilename
Gentooanyallwww-client/chromium<Β 84.0.4147.135UNKNOWN
Gentooanyallwww-client/google-chrome<Β 84.0.4147.135UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.008

Percentile

82.0%