Vulnerability CVE-2020-6460: Information

Description

Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Published: May 21, 2020
Modified: Oct. 5, 2022

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://crbug.com/1063566
  • Permissions Required
  • Vendor Advisory
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
  • Release Notes
  • Vendor Advisory
DSA-4714
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excliding
      81.0.4044.122

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*