Vulnerability Name:

CVE-2020-6549 (CCN-186440)

Assigned:2020-08-10
Published:2020-08-10
Updated:2021-07-21
Summary:Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-416
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-6549

Source: MISC
Type: Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/159558/Chrome-MediaElementEventListener-UpdateSources-Use-After-Free.html

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: MISC
Type: Release Notes, Vendor Advisory
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html

Source: MISC
Type: Permissions Required, Third Party Advisory
https://crbug.com/1105426

Source: XF
Type: UNKNOWN
google-chrome-cve20206549-code-exec(186440)

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-6da740d38c

Source: CCN
Type: Packet Storm Security [10-14-2020]
Chrome MediaElementEventListener::UpdateSources Use-After-Free

Source: GENTOO
Type: Third Party Advisory
GLSA-202101-30

Source: DEBIAN
Type: Third Party Advisory
DSA-4824

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 84.0.4147.125)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:google:chrome:84:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20206549
    V
    CVE-2020-6549
    2022-06-30
    oval:org.opensuse.security:def:112066
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:64807
    P
    Security update for speex (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:64784
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:64597
    P
    Security update for fetchmail (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:105615
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:63237
    P
    sblim-sfcb-1.4.9-3.7 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64575
    P
    Security update for ghostscript (Critical)
    2021-09-15
    oval:org.opensuse.security:def:64574
    P
    Security update for wireshark (Moderate)
    2021-09-13
    oval:org.opensuse.security:def:63090
    P
    gv-3.7.4-1.41 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63430
    P
    libgstaudio-1_0-0-32bit-1.16.2-2.12 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63059
    P
    python2-numpy-gnu-hpc-1.16.5-1.164 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63316
    P
    apache2-mod_auth_openidc-2.3.8-3.7.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63454
    P
    python2-opencv-3.3.1-6.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63057
    P
    libmunge2-0.5.14-11.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62811
    P
    librsvg-devel-2.46.5-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62835
    P
    vorbis-tools-1.4.0-1.53 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63031
    P
    perl-Archive-Extract-0.80-1.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63034
    P
    perl-Mail-SpamAssassin-Plugin-iXhash2-2.05-12.10.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63027
    P
    ocaml-4.05.0-13.5 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64705
    P
    Security update for umoci (Important)
    2021-07-27
    oval:org.opensuse.security:def:63553
    P
    libreoffice-6.0.4.2-1.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63530
    P
    bogofilter-common-1.2.4-1.40 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64503
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:64682
    P
    Security update for avahi (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:64461
    P
    Security update for flatpak, libostree, xdg-desktop-portal, xdg-desktop-portal-gtk (Important)
    2021-04-07
    oval:org.opensuse.security:def:64598
    P
    Security update for java-11-openjdk (Important)
    2021-02-09
    oval:org.opensuse.security:def:64479
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:64325
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:62611
    P
    ImageMagick-7.0.7.34-8.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62658
    P
    libXt6-32bit-1.1.5-2.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63050
    P
    python2-numpy-gnu-hpc-1.14.0-2.105 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63292
    P
    ovmf-201911-5.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62635
    P
    gnome-settings-daemon-3.34.2+0-2.12 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62610
    P
    wireshark-devel-2.4.14-3.25.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63114
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62634
    P
    gnome-desktop-lang-3.34.4-1.32 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63082
    P
    libcgroup-devel-0.41.rc1-1.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63054
    P
    libnss_slurm2-20.02.3-1.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63260
    P
    dpdk-19.11.1-1.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:64438
    P
    Security update for python-cryptography (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:64391
    P
    libtag1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64141
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64109
    P
    Security update for bluez (Important)
    2020-12-01
    oval:org.opensuse.security:def:74545
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:63756
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:63903
    P
    Security update for soundtouch (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74443
    P
    Security update for gdal (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64842
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:64132
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:74569
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:64954
    P
    Security update for autoyast2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64223
    P
    c-ares-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63656
    P
    Security update for MozillaFirefox, mozilla-nspr and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:74896
    P
    Security update for jasper (Low)
    2020-12-01
    oval:org.opensuse.security:def:64865
    P
    Security update for podman, slirp4netns and libcontainers-common (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63983
    P
    Security update for openssl-1_0_0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75029
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:64977
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64367
    P
    libpcsclite1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64247
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64117
    P
    Security update for squid (Important)
    2020-12-01
    oval:org.opensuse.security:def:63680
    P
    Security update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:74919
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:63733
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:64349
    P
    libminizip1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64007
    P
    Security update for libpng16 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75052
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:63880
    P
    Security update for openwsman (Important)
    2020-12-01
    oval:org.opensuse.security:def:74419
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:110747
    P
    Security update for opera (Important)
    2020-09-02
    oval:org.opensuse.security:def:110193
    P
    Security update for opera (Important)
    2020-09-02
    oval:org.opensuse.security:def:103039
    P
    Security update for chromium (Important)
    2020-08-15
    oval:org.opensuse.security:def:93503
    P
    Security update for chromium (Important)
    2020-08-15
    oval:org.opensuse.security:def:96349
    P
    Security update for chromium (Important)
    2020-08-15
    oval:org.opensuse.security:def:100216
    P
    Security update for chromium (Important)
    2020-08-15
    oval:org.opensuse.security:def:109696
    P
    Security update for chromium (Important)
    2020-08-15
    oval:org.opensuse.security:def:110724
    P
    Security update for chromium (Important)
    2020-08-14
    oval:org.opensuse.security:def:110169
    P
    Security update for chromium (Important)
    2020-08-14
    BACK
    google chrome *
    debian debian linux 10.0
    fedoraproject fedora 33
    google chrome 84