Lucene search

K
redhatRedHatRHSA-2020:3377
HistoryAug 10, 2020 - 6:22 a.m.

(RHSA-2020:3377) Critical: chromium-browser security update

2020-08-1006:22:50
access.redhat.com
57

0.196 Low

EPSS

Percentile

96.3%

Chromium is an open-source web browser, powered by WebKit (Blink).

This update upgrades Chromium to version 84.0.4147.105.

Security Fix(es):

  • chromium-browser: Heap buffer overflow in background fetch (CVE-2020-6510)

  • chromium-browser: Side-channel information leakage in content security policy (CVE-2020-6511)

  • chromium-browser: Type Confusion in V8 (CVE-2020-6512)

  • chromium-browser: Heap buffer overflow in PDFium (CVE-2020-6513)

  • chromium-browser: Inappropriate implementation in WebRTC (CVE-2020-6514)

  • chromium-browser: Use after free in tab strip (CVE-2020-6515)

  • chromium-browser: Policy bypass in CORS (CVE-2020-6516)

  • chromium-browser: Heap buffer overflow in history (CVE-2020-6517)

  • chromium-browser: Use after free in SCTP (CVE-2020-6532)

  • chromium-browser: Type Confusion in V8 (CVE-2020-6537)

  • chromium-browser: Inappropriate implementation in WebView (CVE-2020-6538)

  • chromium-browser: Use after free in CSS (CVE-2020-6539)

  • chromium-browser: Heap buffer overflow in Skia (CVE-2020-6540)

  • chromium-browser: Use after free in WebUSB (CVE-2020-6541)

  • chromium-browser: Use after free in developer tools (CVE-2020-6518)

  • chromium-browser: Policy bypass in CSP (CVE-2020-6519)

  • chromium-browser: Heap buffer overflow in Skia (CVE-2020-6520)

  • chromium-browser: Side-channel information leakage in autofill (CVE-2020-6521)

  • chromium-browser: Inappropriate implementation in external protocol handlers (CVE-2020-6522)

  • chromium-browser: Out of bounds write in Skia (CVE-2020-6523)

  • chromium-browser: Heap buffer overflow in WebAudio (CVE-2020-6524)

  • chromium-browser: Heap buffer overflow in Skia (CVE-2020-6525)

  • chromium-browser: Inappropriate implementation in iframe sandbox (CVE-2020-6526)

  • chromium-browser: Insufficient policy enforcement in CSP (CVE-2020-6527)

  • chromium-browser: Incorrect security UI in basic auth (CVE-2020-6528)

  • chromium-browser: Inappropriate implementation in WebRTC (CVE-2020-6529)

  • chromium-browser: Out of bounds memory access in developer tools (CVE-2020-6530)

  • chromium-browser: Side-channel information leakage in scroll to text (CVE-2020-6531)

  • chromium-browser: Type Confusion in V8 (CVE-2020-6533)

  • chromium-browser: Heap buffer overflow in WebRTC (CVE-2020-6534)

  • chromium-browser: Insufficient data validation in WebUI (CVE-2020-6535)

  • chromium-browser: Incorrect security UI in PWAs (CVE-2020-6536)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.