Vulnerability CVE-2020-6463: Information

Description

Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: May 21, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-787CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus81.0.4044.138-alt1125.0.6422.141-alt1ALT-PU-2020-1962-1251690Fixed
chromiump1081.0.4044.138-alt1119.0.6045.159-alt0.p10.1ALT-PU-2020-1962-1251690Fixed
chromiump981.0.4044.138-alt197.0.4692.99-alt0.p9.1ALT-PU-2020-1969-1251727Fixed
chromiumc10f181.0.4044.138-alt1110.0.5481.177-alt1.p10.1ALT-PU-2020-1962-1251690Fixed
chromiumc9f281.0.4044.138-alt184.0.4147.105-alt1.1.p9ALT-PU-2020-1969-1251727Fixed
chromiump1181.0.4044.138-alt1125.0.6422.141-alt1ALT-PU-2020-1962-1251690Fixed
chromium-gostsisyphus83.0.4103.61-alt3124.0.6367.78-alt1ALT-PU-2020-2420-1255177Fixed
chromium-gostp1083.0.4103.61-alt3110.0.5481.177-alt1.p10.1ALT-PU-2020-2420-1255177Fixed
chromium-gostp983.0.4103.61-alt2.M90P.196.0.4664.45-alt2.p9.1ALT-PU-2020-2441-1255237Fixed
chromium-gostc10f183.0.4103.61-alt3110.0.5481.177-alt1.p10.1ALT-PU-2020-2420-1255177Fixed
chromium-gostc9f283.0.4103.61-alt2.M90P.196.0.4664.45-alt2.c9.1ALT-PU-2020-2441-1255237Fixed
chromium-gostp1183.0.4103.61-alt3124.0.6367.78-alt1ALT-PU-2020-2420-1255177Fixed
firefoxsisyphus79.0-alt1126.0.1-alt1ALT-PU-2020-2598-1256176Fixed
firefoxp1079.0-alt1118.0.2-alt0.p10.1ALT-PU-2020-2598-1256176Fixed
firefoxp980.0.1-alt0.1.p9105.0.1-alt0.c9.1ALT-PU-2020-3442-1262506Fixed
firefoxc10f179.0-alt1112.0.2-alt0.p10.1ALT-PU-2020-2598-1256176Fixed
firefoxc9f293.0-alt0.p9.1105.0.1-alt0.c9.1ALT-PU-2021-3368-1288792Fixed
firefoxp1179.0-alt1126.0.1-alt1ALT-PU-2020-2598-1256176Fixed
firefox-esrsisyphus78.1.0-alt1115.11.0-alt1ALT-PU-2020-2466-1255488Fixed
firefox-esrp1078.1.0-alt1115.11.0-alt1ALT-PU-2020-2466-1255488Fixed
firefox-esrp978.3.0-alt0.1.p9102.11.0-alt0.c9.1ALT-PU-2020-2933-1254920Fixed
firefox-esrc10f178.1.0-alt1115.9.1-alt0.c10.1ALT-PU-2020-2466-1255488Fixed
firefox-esrc9f278.7.1-alt0.1.c9102.12.0-alt0.c9.1ALT-PU-2021-1368-1264611Fixed
firefox-esrp1178.1.0-alt1115.11.0-alt1ALT-PU-2020-2466-1255488Fixed
thunderbirdsisyphus78.1.1-alt1115.9.0-alt1ALT-PU-2020-2709-1256264Fixed
thunderbirdp1078.1.1-alt1115.9.0-alt1ALT-PU-2020-2709-1256264Fixed
thunderbirdp978.3.1-alt1102.11.0-alt0.c9.1ALT-PU-2020-2934-1254920Fixed
thunderbirdc10f178.1.1-alt1115.9.0-alt0.c10.1ALT-PU-2020-2709-1256264Fixed
thunderbirdc9f278.7.0-alt0.1.c9102.11.0-alt0.c9.1ALT-PU-2021-1369-1264611Fixed
thunderbirdp1178.1.1-alt1115.9.0-alt1ALT-PU-2020-2709-1256264Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://crbug.com/1065186
  • Issue Tracking
  • Vendor Advisory
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
  • Release Notes
  • Vendor Advisory
openSUSE-SU-2020:0823
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2020:0832
  • Mailing List
  • Third Party Advisory
DSA-4714
  • Third Party Advisory
[debian-lts-announce] 20200729 [SECURITY] [DLA 2297-1] firefox-esr security update
  • Mailing List
  • Third Party Advisory
GLSA-202007-60
  • Third Party Advisory
DSA-4736
  • Third Party Advisory
GLSA-202007-64
  • Third Party Advisory
[debian-lts-announce] 20200802 [SECURITY] [DLA 2310-1] thunderbird security update
  • Mailing List
  • Third Party Advisory
DSA-4740
  • Third Party Advisory
openSUSE-SU-2020:1147
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2020:1155
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2020:1179
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2020:1189
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2020:1205
  • Mailing List
  • Third Party Advisory
USN-4443-1
  • Third Party Advisory
FEDORA-2020-08561721ad
    FEDORA-2020-77f89ab772
        1. Configuration 1

          cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
          End excliding
          81.0.4044.122

          Configuration 2

          cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

          cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

          Configuration 3

          cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

          cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

          cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

          Configuration 4

          cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

          cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

          Configuration 5

          cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

          cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*

          cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*