CVE-2020-6381: Insufficient policy enforcement in Blink.
An integer overflow flaw was found in the JavaScript component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1034394
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Other sources
Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Upgrade
Upgrade
Chromium / Google Chrome (JavaScript component)to a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Compensating control
Mitigate the Blink policy enforcement gap by ensuring Blink policy enforcement is sufficient (e.g., apply vendor mitigations/workarounds for the referenced issue) until the JavaScript integer overflow is patched.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-6382
- CVE-2019-18197
- CVE-2019-19926
- CVE-2020-6385
- CVE-2019-19880
- CVE-2019-19925
- CVE-2020-6387
- CVE-2020-6388
- CVE-2020-6389
- CVE-2020-6390
- CVE-2020-6391
- CVE-2020-6392
- CVE-2020-6393
- CVE-2020-6499
- CVE-2020-6394
- CVE-2020-6395
- CVE-2020-6396
- CVE-2020-6397
- CVE-2020-6398
- CVE-2020-6399
- CVE-2020-6500
- CVE-2020-6400
- CVE-2020-6401
- CVE-2020-6402
- CVE-2020-6501
- CVE-2020-6403
- CVE-2020-6404
- CVE-2020-6405
- CVE-2020-6406
- CVE-2019-19923
- CVE-2020-6408
- CVE-2020-6409
- CVE-2020-6410
- CVE-2020-6411
- CVE-2020-6502
- CVE-2020-6412
- CVE-2020-6413
- CVE-2020-6414
- CVE-2020-6415
- CVE-2020-6416
- CVE-2020-6417
Frequently Asked Questions
What is CVE-2020-6381?
CVE-2020-6381 is a vulnerability in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87.
How can a remote attacker exploit CVE-2020-6381?
A remote attacker can potentially exploit CVE-2020-6381 through heap corruption via a crafted HTML page.
What is the severity of CVE-2020-6381?
CVE-2020-6381 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2020-6381?
Chrome versions prior to 80.0.3987.87 on ChromeOS and Android are affected by CVE-2020-6381.
How do I fix CVE-2020-6381?
Update your Chrome browser to version 80.0.3987.87 or later.