Vulnerability Name:

CVE-2020-6556 (CCN-186897)

Assigned:2020-08-18
Published:2020-08-18
Updated:2022-06-29
Summary:Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-6556

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1713

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: MISC
Type: Vendor Advisory
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_18.html

Source: MISC
Type: Third Party Advisory
https://crbug.com/1115345

Source: XF
Type: UNKNOWN
google-chrome-cve20206556-bo(186897)

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-6da740d38c

Source: DEBIAN
Type: Third Party Advisory
DSA-4824

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 84.0.4147.125)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:google:chrome:84:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20206556
    V
    CVE-2020-6556
    2022-06-30
    oval:org.opensuse.security:def:112066
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:64773
    P
    Security update for glibc (Moderate)
    2021-12-08
    oval:org.opensuse.security:def:64793
    P
    Security update for qemu (Important)
    2021-11-03
    oval:org.opensuse.security:def:64584
    P
    Security update for git (Low)
    2021-10-06
    oval:org.opensuse.security:def:64583
    P
    Security update for curl (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:105615
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:63246
    P
    xen-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64571
    P
    Security update for apache2 (Important)
    2021-09-03
    oval:org.opensuse.security:def:63328
    P
    frr-7.4-2.25 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63444
    P
    nping-7.70-3.12.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63122
    P
    aws-cli-1.18.117-8.11.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63384
    P
    vsftpd-3.0.3-7.16.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63125
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63522
    P
    tiff-4.0.9-5.30.28 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62825
    P
    python-tk-2.7.18-7.55.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63040
    P
    policycoreutils-devel-3.0-1.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63043
    P
    rpm-build-4.14.1-29.46 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63036
    P
    perl-PerlMagick-7.0.7.34-10.15.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64529
    P
    Security update for postgresql12 (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:63539
    P
    gnome-shell-calendar-3.26.2+20180130.0d9c74212-2.43 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63068
    P
    reiserfs-kmp-default-4.12.14-23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:74637
    P
    Security update for hivex (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:64691
    P
    Security update for fribidi (Important)
    2021-05-19
    oval:org.opensuse.security:def:64493
    P
    Security update for python3 (Moderate)
    2021-05-11
    oval:org.opensuse.security:def:64459
    P
    Security update for gssproxy (Moderate)
    2021-04-06
    oval:org.opensuse.security:def:64666
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:64665
    P
    Security update for openssl-1_1 (Moderate)
    2021-03-09
    oval:org.opensuse.security:def:64447
    P
    Security update for the Linux Kernel (Important)
    2020-12-10
    oval:org.opensuse.security:def:63150
    P
    freeradius-server-3.0.16-1.41 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62625
    P
    file-roller-3.32.5-1.8 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62648
    P
    libICE6-32bit-1.0.9-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63118
    P
    python3-keystoneclient-3.15.0-2.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63621
    P
    icedtea-web-1.7.1-5.13 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62703
    P
    libthai0-32bit-0.1.27-1.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62624
    P
    fetchmailconf-6.3.26-3.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63104
    P
    apache2-mod_wsgi-4.5.18-2.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62726
    P
    wireshark-devel-3.2.2-3.35.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63306
    P
    subversion-server-1.10.6-3.6.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62903
    P
    jython-2.2.1-4.36 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62702
    P
    libtag-devel-1.11.1-4.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63182
    P
    skopeo-0.1.26-2.39 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:64381
    P
    libsha1detectcoll-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64315
    P
    libXxf86vm-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64131
    P
    Security update for python-ipaddress (Important)
    2020-12-01
    oval:org.opensuse.security:def:63748
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74987
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63742
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:64417
    P
    minicom on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64075
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75120
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:63889
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74433
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:64209
    P
    apparmor-abstractions on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64118
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:74559
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63824
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:63971
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74511
    P
    Security update for libvpx (Important)
    2020-12-01
    oval:org.opensuse.security:def:64851
    P
    Security update for gpg2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:64200
    P
    ruby2.5-rubygem-nokogiri on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64963
    P
    Security update for sysstat (Low)
    2020-12-01
    oval:org.opensuse.security:def:64875
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64237
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63670
    P
    Security update for hostinfo, supportutils (Important)
    2020-12-01
    oval:org.opensuse.security:def:74905
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64933
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64339
    P
    libjpeg62 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63997
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75038
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65045
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:110261
    P
    Security update for opera (Important)
    2020-10-23
    oval:org.opensuse.security:def:110815
    P
    Security update for opera (Important)
    2020-10-23
    oval:org.opensuse.security:def:110733
    P
    Security update for chromium (Moderate)
    2020-08-26
    oval:org.opensuse.security:def:110183
    P
    Security update for chromium (Moderate)
    2020-08-26
    BACK
    google chrome *
    debian debian linux 10.0
    fedoraproject fedora 33
    opensuse leap 15.1
    opensuse leap 15.2
    google chrome 84