Vulnerability Name:

CVE-2020-15960

Assigned:2020-09-21
Published:2020-09-21
Updated:2021-01-29
Summary:Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-787
References:Source: MITRE
Type: CNA
CVE-2020-15960

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1527

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1542

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1550

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1713

Source: MISC
Type: Release Notes, Vendor Advisory
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html

Source: MISC
Type: Exploit, Issue Tracking, Patch, Vendor Advisory
https://crbug.com/1100136

Source: FEDORA
Type: Third Party Advisory
FEDORA-2020-aea86f913e

Source: FEDORA
Type: Third Party Advisory
FEDORA-2020-2d994b986d

Source: FEDORA
Type: Third Party Advisory
FEDORA-2020-214865ce21

Source: GENTOO
Type: Third Party Advisory
GLSA-202009-13

Source: GENTOO
Type: Third Party Advisory
GLSA-202101-30

Source: DEBIAN
Type: Third Party Advisory
DSA-4824

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 85.0.4183.121)

  • Configuration 2:
  • cpe:/a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.2:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2020-15960 (CCN-188625)

    Assigned:2020-09-21
    Published:2020-09-21
    Updated:2021-01-29
    Summary:Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
    CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
    7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): Required
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): High
    Integrity (I): High
    Availibility (A): High
    8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
    7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): Required
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): High
    Integrity (I): High
    Availibility (A): High
    CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
    Exploitability Metrics:Access Vector (AV): Network
    Access Complexity (AC): Medium
    Authentication (Au): None
    Impact Metrics:Confidentiality (C): Partial
    Integrity (I): Partial
    Availibility (A): Partial
    9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
    Exploitability Metrics:Access Vector (AV): Network
    Access Complexity (AC): Low
    Athentication (Au): Single_Instance
    Impact Metrics:Confidentiality (C): Complete
    Integrity (I): Complete
    Availibility (A): Complete
    Vulnerability Type:CWE-787
    Vulnerability Consequences:Gain Access
    References:Source: MITRE
    Type: CNA
    CVE-2020-15960

    Source: SUSE
    Type: Mailing List, Third Party Advisory
    openSUSE-SU-2020:1527

    Source: SUSE
    Type: Mailing List, Third Party Advisory
    openSUSE-SU-2020:1542

    Source: SUSE
    Type: Mailing List, Third Party Advisory
    openSUSE-SU-2020:1550

    Source: SUSE
    Type: Mailing List, Third Party Advisory
    openSUSE-SU-2020:1713

    Source: CCN
    Type: Google Chrome Releases Web site
    Stable Channel Update for Desktop

    Source: MISC
    Type: Release Notes, Vendor Advisory
    https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html

    Source: MISC
    Type: Exploit, Issue Tracking, Patch, Vendor Advisory
    https://crbug.com/1100136

    Source: XF
    Type: UNKNOWN
    google-chrome-cve202015960-bo(188625)

    Source: FEDORA
    Type: Third Party Advisory
    FEDORA-2020-aea86f913e

    Source: FEDORA
    Type: Third Party Advisory
    FEDORA-2020-2d994b986d

    Source: FEDORA
    Type: Third Party Advisory
    FEDORA-2020-214865ce21

    Source: GENTOO
    Type: Third Party Advisory
    GLSA-202009-13

    Source: GENTOO
    Type: Third Party Advisory
    GLSA-202101-30

    Source: DEBIAN
    Type: Third Party Advisory
    DSA-4824

    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:202015960
    V
    CVE-2020-15960
    2022-06-30
    oval:org.opensuse.security:def:112066
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:64839
    P
    Security update for libmspack (Low)
    2022-01-13
    oval:org.opensuse.security:def:64773
    P
    Security update for glibc (Moderate)
    2021-12-08
    oval:org.opensuse.security:def:64630
    P
    Security update for brotli (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:64629
    P
    Security update for wireshark (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:105615
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:64571
    P
    Security update for apache2 (Important)
    2021-09-03
    oval:org.opensuse.security:def:63328
    P
    frr-7.4-2.25 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63348
    P
    libshibsp-lite8-3.1.0-1.30 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63089
    P
    cyrus-sasl-bdb-2.1.27-2.2 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63486
    P
    libjpeg-turbo-1.5.3-5.15.7 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63122
    P
    aws-cli-1.18.117-8.11.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63384
    P
    vsftpd-3.0.3-7.16.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63125
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63522
    P
    tiff-4.0.9-5.30.28 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:64737
    P
    Security update for bluez (Moderate)
    2021-07-22
    oval:org.opensuse.security:def:64535
    P
    Security update for apache2 (Important)
    2021-06-22
    oval:org.opensuse.security:def:64529
    P
    Security update for postgresql12 (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:62867
    P
    pam-devel-32bit-1.3.0-4.10 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:74637
    P
    Security update for hivex (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:64493
    P
    Security update for python3 (Moderate)
    2021-05-11
    oval:org.opensuse.security:def:64459
    P
    Security update for gssproxy (Moderate)
    2021-04-06
    oval:org.opensuse.security:def:64666
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:64665
    P
    Security update for openssl-1_1 (Moderate)
    2021-03-09
    oval:org.opensuse.security:def:64279
    P
    Security update for webkit2gtk3 (Important)
    2020-12-17
    oval:org.opensuse.security:def:63585
    P
    libmwaw-0_3-3-0.3.14-4.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63150
    P
    freeradius-server-3.0.16-1.41 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62667
    P
    libexif-devel-0.6.21-5.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62690
    P
    libout123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63118
    P
    python3-keystoneclient-3.15.0-2.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63621
    P
    icedtea-web-1.7.1-5.13 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62703
    P
    libthai0-32bit-0.1.27-1.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62666
    P
    libexempi-devel-2.4.5-3.3.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63146
    P
    davfs2-1.5.4-1.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62726
    P
    wireshark-devel-3.2.2-3.35.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63086
    P
    openldap2-back-meta-2.4.46-9.28.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62903
    P
    jython-2.2.1-4.36 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62702
    P
    libtag-devel-1.11.1-4.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63182
    P
    skopeo-0.1.26-2.39 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63114
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63292
    P
    ovmf-201911-5.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63082
    P
    libcgroup-devel-0.41.rc1-1.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:64423
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64315
    P
    libXxf86vm-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64173
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63748
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74987
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63788
    P
    Security update for djvulibre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64417
    P
    minicom on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64075
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75120
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:63935
    P
    Security update for libssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:74475
    P
    Security update for freerdp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64209
    P
    apparmor-abstractions on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64164
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74601
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:63824
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:63971
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74511
    P
    Security update for libvpx (Important)
    2020-12-01
    oval:org.opensuse.security:def:64897
    P
    Security update for sysstat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64200
    P
    ruby2.5-rubygem-nokogiri on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65009
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64875
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63712
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:74951
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:64933
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64381
    P
    libsha1detectcoll-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64039
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:75084
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:65045
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:100238
    P
    (Important)
    2020-10-29
    oval:org.opensuse.security:def:110261
    P
    Security update for opera (Important)
    2020-10-23
    oval:org.opensuse.security:def:110815
    P
    Security update for opera (Important)
    2020-10-23
    oval:org.opensuse.security:def:109717
    P
    Security update for chromium (Important)
    2020-09-27
    oval:org.opensuse.security:def:103060
    P
    Security update for chromium (Important)
    2020-09-27
    oval:org.opensuse.security:def:96370
    P
    Security update for chromium (Important)
    2020-09-27
    oval:org.opensuse.security:def:93525
    P
    Security update for chromium (Important)
    2020-09-26
    oval:org.opensuse.security:def:110779
    P
    Security update for chromium (Important)
    2020-09-25
    oval:org.opensuse.security:def:110225
    P
    Security update for chromium (Important)
    2020-09-25
    BACK
    google chrome *
    opensuse backports sle 15.0 sp1
    opensuse backports sle 15.0 sp2
    opensuse leap 15.1
    opensuse leap 15.2
    fedoraproject fedora 31
    fedoraproject fedora 32
    fedoraproject fedora 33
    debian debian linux 10.0