CVE-2020-6455: High severity Google Chrome vulnerability
Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-6455.
Which software is affected by CVE-2020-6455?
Google Chrome prior to version 81.0.4044.92, Debian Linux 9.0 and 10.0, Fedora 30, 31, and 32, openSUSE Leap 15.1, and Debian Chromium package.
What is the severity of CVE-2020-6455?
The severity of CVE-2020-6455 is high, with a severity value of 8.8.
How can an attacker exploit CVE-2020-6455?
An attacker can potentially exploit heap corruption via a crafted HTML page.
How to fix CVE-2020-6455?
Update Google Chrome to version 81.0.4044.92 or later, update Debian Linux to the provided versions, update Fedora to the latest version, update openSUSE Leap to version 15.1, or update the Debian Chromium package.