vulnerability

FreeBSD: VID-F4722927-1375-11EB-8711-3065EC8FD3EC (CVE-2020-16002): chromium -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Oct 20, 2020
Added
Oct 22, 2020
Modified
Dec 16, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-F4722927-1375-11EB-8711-3065EC8FD3EC:




Chrome Releases reports:



This release includes 5 security fixes:



[1125337] High CVE-2020-16000: Inappropriate implementation in


Blink. Reported by amaebi_jp on 2020-09-06


[1135018] High CVE-2020-16001: Use after free in media.


Reported by Khalil Zhani on 2020-10-05


[1137630] High CVE-2020-16002: Use after free in PDFium.


Reported by Weipeng Jiang (@Krace) from Codesafe Team of Legendsec


at Qi'anxin Group on 2020-10-13


[1139963] High CVE-2020-15999: Heap buffer overflow in


Freetype. Reported by Sergei Glazunov of Google Project Zero on


2020-10-19


[1134960] Medium CVE-2020-16003: Use after free in printing.


Reported by Khalil Zhani on 2020-10-04





Solution

freebsd-upgrade-package-chromium
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.