Lucene search

K
redhatRedHatRHSA-2020:3560
HistoryAug 26, 2020 - 1:58 p.m.

(RHSA-2020:3560) Important: chromium-browser security update

2020-08-2613:58:36
access.redhat.com
39
chromium-browser
security update
web browser
cve-2020-6542
cve-2020-6543
cve-2020-6544
cve-2020-6545
cve-2020-6546
cve-2020-6547
cve-2020-6548
cve-2020-6549
cve-2020-6550
cve-2020-6551
cve-2020-6552
cve-2020-6553
cve-2020-6556
cve-2020-6554
cve-2020-6555

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.267

Percentile

96.8%

Chromium is an open-source web browser, powered by WebKit (Blink).

This update upgrades Chromium to version 84.0.4147.135.

Security Fix(es):

  • chromium-browser: Use after free in ANGLE (CVE-2020-6542)

  • chromium-browser: Use after free in task scheduling (CVE-2020-6543)

  • chromium-browser: Use after free in media (CVE-2020-6544)

  • chromium-browser: Use after free in audio (CVE-2020-6545)

  • chromium-browser: Inappropriate implementation in installer (CVE-2020-6546)

  • chromium-browser: Incorrect security UI in media (CVE-2020-6547)

  • chromium-browser: Heap buffer overflow in Skia (CVE-2020-6548)

  • chromium-browser: Use after free in media (CVE-2020-6549)

  • chromium-browser: Use after free in IndexedDB (CVE-2020-6550)

  • chromium-browser: Use after free in WebXR (CVE-2020-6551)

  • chromium-browser: Use after free in Blink (CVE-2020-6552)

  • chromium-browser: Use after free in offline mode (CVE-2020-6553)

  • chromium-browser: Heap buffer overflow in SwiftShader (CVE-2020-6556)

  • chromium-browser: Use after free in extensions (CVE-2020-6554)

  • chromium-browser: Out of bounds read in WebGL (CVE-2020-6555)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.267

Percentile

96.8%