Vulnerability Name:

CVE-2020-6539 (CCN-185976)

Assigned:2020-07-27
Published:2020-07-27
Updated:2021-07-21
Summary:Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-416
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-6539

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: MISC
Type: Release Notes, Vendor Advisory
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html

Source: MISC
Type: Permissions Required, Vendor Advisory
https://crbug.com/1105635

Source: XF
Type: UNKNOWN
google-chrome-cve20206539-code-exec(185976)

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-6da740d38c

Source: DEBIAN
Type: Third Party Advisory
DSA-4824

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 84.0.4147.105)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:google:chrome:84:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20206539
    V
    CVE-2020-6539
    2022-06-30
    oval:org.opensuse.security:def:112066
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:64826
    P
    Security update for log4j12 (Important)
    2021-12-17
    oval:org.opensuse.security:def:64807
    P
    Security update for speex (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:64597
    P
    Security update for fetchmail (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:105615
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:64768
    P
    Security update for samba (Important)
    2021-09-22
    oval:org.opensuse.security:def:63221
    P
    libvirglrenderer0-0.6.0-2.30 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64559
    P
    Security update for aspell (Important)
    2021-08-20
    oval:org.opensuse.security:def:64558
    P
    Security update for fetchmail (Moderate)
    2021-08-20
    oval:org.opensuse.security:def:63514
    P
    python2-opencv-3.3.1-6.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63417
    P
    nodejs14-14.16.0-5.9.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63316
    P
    apache2-mod_auth_openidc-2.3.8-3.7.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63057
    P
    libmunge2-0.5.14-11.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63454
    P
    python2-opencv-3.3.1-6.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62798
    P
    libmms-devel-0.6.4-1.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63015
    P
    jackson-databind-2.10.5.1-3.3.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62835
    P
    vorbis-tools-1.4.0-1.53 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63018
    P
    jython-2.2.1-11.65 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63043
    P
    rpm-build-4.14.1-29.46 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63011
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64705
    P
    Security update for umoci (Important)
    2021-07-27
    oval:org.opensuse.security:def:63553
    P
    libreoffice-6.0.4.2-1.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64503
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:63077
    P
    pam-modules-12.1-3.17 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:64466
    P
    Security update for cifs-utils (Moderate)
    2021-04-13
    oval:org.opensuse.security:def:64461
    P
    Security update for flatpak, libostree, xdg-desktop-portal, xdg-desktop-portal-gtk (Important)
    2021-04-07
    oval:org.opensuse.security:def:64666
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:64598
    P
    Security update for java-11-openjdk (Important)
    2021-02-09
    oval:org.opensuse.security:def:63082
    P
    libcgroup-devel-0.41.rc1-1.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62598
    P
    pulseaudio-11.1-4.31 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63260
    P
    dpdk-19.11.1-1.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62621
    P
    emacs-x11-25.3-3.3.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63050
    P
    python2-numpy-gnu-hpc-1.14.0-2.105 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62635
    P
    gnome-settings-daemon-3.34.2+0-2.12 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62597
    P
    ppp-2.4.7-3.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62658
    P
    libXt6-32bit-1.1.5-2.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63279
    P
    librelp-devel-1.2.15-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62634
    P
    gnome-desktop-lang-3.34.4-1.32 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63114
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63054
    P
    libnss_slurm2-20.02.3-1.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63643
    P
    strongswan-nm-5.8.2-9.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:64354
    P
    libnetpbm11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64247
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64104
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63680
    P
    Security update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:74919
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:63717
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64349
    P
    libminizip1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64007
    P
    Security update for libpng16 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75052
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:63864
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74406
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:64391
    P
    libtag1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64141
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64093
    P
    Security update for apache-commons-httpclient (Important)
    2020-12-01
    oval:org.opensuse.security:def:74532
    P
    Security update of chromium (Low)
    2020-12-01
    oval:org.opensuse.security:def:63756
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:64422
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63903
    P
    Security update for soundtouch (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74443
    P
    Security update for gdal (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64132
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:74569
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:64938
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:64210
    P
    apr-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74880
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64865
    P
    Security update for podman, slirp4netns and libcontainers-common (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64312
    P
    libXvMC-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63970
    P
    Security update for unzip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75013
    P
    Security update of chromium (Low)
    2020-12-01
    oval:org.opensuse.security:def:64977
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:110193
    P
    Security update for opera (Important)
    2020-09-02
    oval:org.opensuse.security:def:110747
    P
    Security update for opera (Important)
    2020-09-02
    oval:org.opensuse.security:def:109693
    P
    Security update of chromium (Low)
    2020-08-12
    oval:org.opensuse.security:def:103036
    P
    Security update of chromium (Low)
    2020-08-12
    oval:org.opensuse.security:def:96346
    P
    Security update of chromium (Low)
    2020-08-12
    oval:org.opensuse.security:def:100213
    P
    Security update of chromium (Low)
    2020-08-07
    oval:org.opensuse.security:def:93500
    P
    Security update of chromium (Low)
    2020-08-07
    oval:org.opensuse.security:def:110708
    P
    Security update of chromium (Low)
    2020-08-06
    oval:org.opensuse.security:def:110156
    P
    Security update of chromium (Low)
    2020-08-06
    BACK
    google chrome *
    debian debian linux 10.0
    fedoraproject fedora 33
    google chrome 84