Vulnerability Name:

CVE-2020-6377 (CCN-174066)

Assigned:2020-01-07
Published:2020-01-07
Updated:2022-04-08
Summary:Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-416
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-6377

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:0006

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:0009

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:0053

Source: REDHAT
Type: Third Party Advisory
RHSA-2020:0084

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: MISC
Type: Vendor Advisory
https://chromereleases.googleblog.com/2020/01/stable-channel-update-for-desktop.html

Source: MISC
Type: Exploit, Issue Tracking, Patch, Vendor Advisory
https://crbug.com/1029462

Source: XF
Type: UNKNOWN
chrome-audio-code-execution(174066)

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-4355ea258e

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-581537c8aa

Source: BUGTRAQ
Type: Mailing List, Third Party Advisory
20200120 [SECURITY] [DSA 4606-1] chromium security update

Source: GENTOO
Type: Third Party Advisory
GLSA-202003-08

Source: DEBIAN
Type: Third Party Advisory
DSA-4606

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 79.0.3945.117)

  • Configuration 2:
  • cpe:/a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:google:chrome:79.0.3906.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:93623
    P
    (Important)
    2022-07-08
    oval:org.opensuse.security:def:20206377
    V
    CVE-2020-6377
    2022-06-30
    oval:org.opensuse.security:def:112066
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:93588
    P
    (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:64597
    P
    Security update for fetchmail (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:93580
    P
    (Important)
    2021-10-15
    oval:org.opensuse.security:def:100336
    P
    (Important)
    2021-10-15
    oval:org.opensuse.security:def:105615
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:64767
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:63343
    P
    libopenvswitch-2_14-0-2.14.2-17.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100301
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:100293
    P
    (Important)
    2021-06-10
    oval:org.opensuse.security:def:62847
    P
    checkbashisms-2.15.1-1.49 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62840
    P
    aaa_base-malloccheck-84.87+git20180409.04c9dae-1.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63546
    P
    libmwaw-0_3-3-0.3.13-2.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62872
    P
    perl-Net-Libproxy-0.4.15-2.42 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62844
    P
    bsdtar-3.3.2-1.27 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:74709
    P
    Security update for snakeyaml (Important)
    2021-06-07
    oval:org.opensuse.security:def:64495
    P
    Security update for the Linux Kernel (Important)
    2021-05-12
    oval:org.opensuse.security:def:64655
    P
    Security update for python-cryptography (Important)
    2021-02-25
    oval:org.opensuse.security:def:63050
    P
    python2-numpy-gnu-hpc-1.14.0-2.105 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:64251
    P
    firewall-macros on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25259
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25831
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:64388
    P
    libssh-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25397
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26504
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25632
    P
    Security update for aspell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25056
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:63922
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25131
    P
    Security update for bash (Important)
    2020-12-01
    oval:org.opensuse.security:def:25055
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25787
    P
    Security update for libwmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64387
    P
    libsqlite3-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25340
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26469
    P
    Security update for phpMyAdmin (Important)
    2020-12-01
    oval:org.opensuse.security:def:25481
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25685
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63693
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:25067
    P
    Security update for libjpeg-turbo (Important)
    2020-12-01
    oval:org.opensuse.security:def:74842
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25773
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:110504
    P
    Security update for chromium (Important)
    2020-01-11
    oval:com.ubuntu.disco:def:202063770000000
    V
    CVE-2020-6377 on Ubuntu 19.04 (disco) - medium.
    2020-01-10
    oval:com.ubuntu.bionic:def:202063770000000
    V
    CVE-2020-6377 on Ubuntu 18.04 LTS (bionic) - medium.
    2020-01-10
    oval:com.ubuntu.xenial:def:202063770000000
    V
    CVE-2020-6377 on Ubuntu 16.04 LTS (xenial) - medium.
    2020-01-10
    BACK
    google chrome *
    opensuse backports sle 15.0 sp1
    opensuse leap 15.1
    fedoraproject fedora 30
    fedoraproject fedora 31
    redhat enterprise linux desktop 6.0
    redhat enterprise linux workstation 6.0
    debian debian linux 9.0
    debian debian linux 10.0
    google chrome 79.0.3906.0