Vulnerability Name:

CVE-2020-6401 (CCN-175760)

Assigned:2020-02-04
Published:2020-02-04
Updated:2020-02-17
Summary:Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2020-6401

Source: SUSE
Type: Third Party Advisory
openSUSE-SU-2020:0210

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2020:0233

Source: REDHAT
Type: UNKNOWN
RHSA-2020:0514

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: MISC
Type: Vendor Advisory
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

Source: MISC
Type: Permissions Required
https://crbug.com/1017707

Source: XF
Type: UNKNOWN
google-chrome-cve20206401-sec-bypass(175760)

Source: FEDORA
Type: UNKNOWN
FEDORA-2020-39e0b8bd14

Source: FEDORA
Type: UNKNOWN
FEDORA-2020-f6271d7afa

Source: GENTOO
Type: UNKNOWN
GLSA-202003-08

Source: DEBIAN
Type: UNKNOWN
DSA-4638

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2020-6401

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 80.0.3987.87)

  • Configuration 2:
  • cpe:/a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:google:chrome:80:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20206401
    V
    CVE-2020-6401
    2022-09-02
    oval:org.opensuse.security:def:112066
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:74674
    P
    Security update for binutils (Moderate)
    2021-11-04
    oval:org.opensuse.security:def:64608
    P
    Security update for libvirt (Moderate)
    2021-10-29
    oval:org.opensuse.security:def:105615
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:63218
    P
    libshibsp-lite7-2.6.1-1.48 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63421
    P
    ffmpeg-3.4.2-9.2 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62747
    P
    gd-2.2.5-9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63559
    P
    pidgin-plugin-otr-4.0.2-1.61 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64496
    P
    Security update for openvpn (Moderate)
    2021-05-12
    oval:org.opensuse.security:def:100270
    P
    (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:64454
    P
    Security update for flac (Moderate)
    2020-12-24
    oval:org.opensuse.security:def:62719
    P
    sane-backends-1.0.27-4.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62722
    P
    typelib-1_0-JavaScriptCore-4_0-2.28.2-1.11 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62925
    P
    rpm-build-4.14.1-10.16.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62715
    P
    python-tk-2.7.17-7.38.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25627
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25051
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26464
    P
    Security update for enigmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63785
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25126
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25050
    P
    Security update for nfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64246
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25335
    P
    Security update for u-boot (Important)
    2020-12-01
    oval:org.opensuse.security:def:25768
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25476
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:25826
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25680
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25062
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26499
    P
    Security update for chromium, re2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:64112
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:25254
    P
    Security update for squid (Important)
    2020-12-01
    oval:org.opensuse.security:def:74548
    P
    Security update for hylafax+ (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64352
    P
    libncurses6-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25392
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:25782
    P
    Security update for evolution-data-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:93557
    P
    (Moderate)
    2020-04-07
    oval:com.ubuntu.bionic:def:202064010000000
    V
    CVE-2020-6401 on Ubuntu 18.04 LTS (bionic) - medium.
    2020-02-11
    oval:com.ubuntu.xenial:def:202064010000000
    V
    CVE-2020-6401 on Ubuntu 16.04 LTS (xenial) - medium.
    2020-02-11
    oval:org.opensuse.security:def:110298
    P
    Security update for chromium (Important)
    2020-02-09
    BACK
    google chrome *
    opensuse backports sle 15.0 sp1
    google chrome 80