vulnerability

FreeBSD: VID-BED5D41A-F2B4-11EA-A878-E09467587C17 (CVE-2020-6576): chromium -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Sep 8, 2020
Added
Sep 10, 2020
Modified
Oct 20, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-BED5D41A-F2B4-11EA-A878-E09467587C17:




Chrome Releases reports:



This release contains 5 security fixes:



[1116304] High CVE-2020-6573: Use after free in video. Reported


by Leecraso and Guang Gong of 360 Alpha Lab working with 360


BugCloud on 2020-08-14


[1102196] High CVE-2020-6574: Insufficient policy


enforcement in installer. Reported by CodeColorist of


Ant-Financial LightYear Labs on 2020-07-05


[1081874] High CVE-2020-6575: Race in Mojo. Reported by


Microsoft on 2020-05-12


[1111737] High CVE-2020-6576: Use after free in offscreen


canvas. Reported by Looben Yang on 2020-07-31


[1122684] High CVE-2020-15959: Insufficient policy enforcement


in networking. Reported by Eric Lawrence of Microsoft on


2020-08-27





Solution

freebsd-upgrade-package-chromium
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.