CVE-2020-16008: Stack buffer overflow in WebRTC
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-16008?
CVE-2020-16008 is a vulnerability in WebRTC in Google Chrome that allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
What software is affected by CVE-2020-16008?
Google Chrome versions prior to 86.0.4240.183, openSUSE Backports SLE 15.0 SP1 and SP2, Debian Debian Linux 10.0, Fedoraproject Fedora versions 32 and 33, and openSUSE Leap 15.1 and 15.2 are affected.
What is the severity of CVE-2020-16008?
CVE-2020-16008 has a severity rating of 8.8 (high).
How can I fix CVE-2020-16008?
To fix CVE-2020-16008, update to Google Chrome version 86.0.4240.183 or later, or apply the appropriate patches or updates for the affected software.
Where can I find more information about CVE-2020-16008?
You can find more information about CVE-2020-16008 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html](http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html), [http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00017.html](http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00017.html), [https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html](https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html)