CVE-2020-16007: Insufficient data validation in installer
Published Sep 4, 2020
·Updated
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
Credit
Abdelhamid Naceri (halov)
Affected Software
8 affected componentsFixes available
debian/chromium
90.0.4430.212-1~deb10u1116.0.5845.180-1~deb11u1120.0.6099.129-1~deb11u1119.0.6045.199-1~deb12u1120.0.6099.129-1~deb12u1120.0.6099.129-1
Google Chrome<86.0.4240.183
86.0.4240.183
Google Chrome<86.0.4240.183
openSUSE Backports SLE=15.0-sp1
openSUSE Backports SLE=15.0-sp2
Debian Debian Linux=10.0
openSUSE Leap=15.1
openSUSE Leap=15.2
Event History
Sep 4, 2020
CVE Published
12:00 AM
Nov 3, 2020
CVE Published
via MITRE·02:21 AM
Data Sourced
via MITRE·02:21 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-16007.
2
What is the severity of CVE-2020-16007?
The severity of CVE-2020-16007 is high, with a severity value of 7.8.
3
How does CVE-2020-16007 affect Google Chrome?
CVE-2020-16007 affects Google Chrome versions prior to 86.0.4240.183.
4
How can a local attacker exploit CVE-2020-16007?
A local attacker can potentially elevate privilege by exploiting CVE-2020-16007 through a crafted filesystem.
5
Where can I find more information about CVE-2020-16007?
You can find more information about CVE-2020-16007 in the following references: [link1], [link2], and [link3].