First published: Wed Jul 15 2020(Updated: )
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Credit: natashenka Google Project Zero chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | 120.0.6099.224-1~deb11u1 130.0.6723.91-1~deb12u1 130.0.6723.116-1~deb12u1 130.0.6723.91-2 130.0.6723.116-1 | |
debian/firefox | 132.0.2-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.4.0esr-1~deb11u1 128.3.1esr-1~deb12u1 128.4.0esr-1~deb12u1 128.3.1esr-2 128.4.0esr-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.4.0esr-1~deb11u1 1:115.16.0esr-1~deb12u1 1:128.4.0esr-1~deb12u1 1:128.4.2esr-1 1:128.4.3esr-1 | |
tvOS | <13.4.8 | 13.4.8 |
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Thunderbird | <78.1 | 78.1 |
Thunderbird | <68.11 | 68.11 |
Firefox | <79 | 79 |
Firefox ESR | <68.11 | 68.11 |
Firefox ESR | <78.1 | 78.1 |
Safari | <13.1.2 | 13.1.2 |
Apple iOS and iPadOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and macOS | <13.6 | 13.6 |
Google Chrome | <84.0.4147.89 | |
openSUSE Backports | =15.0-sp1 | |
openSUSE Backports | =15.0-sp2 | |
SUSE Linux | =15.1 | |
SUSE Linux | =15.2 | |
Red Hat Fedora | =31 | |
Red Hat Fedora | =32 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =20.04 | |
Safari | <13.1.2 | |
Apple iOS, iPadOS, and macOS | <13.6 | |
iPhone OS | <13.6 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-6514 is a memory corruption issue in WebRTC that allows bypassing ASLR.
The affected software includes Mozilla Firefox ESR (version up to 68.11), Apple iOS (version up to 13.6), Apple iPadOS (version up to 13.6), Apple Safari (version up to 13.1.2), Apple watchOS (version up to 6.2.8), Apple tvOS (version up to 13.4.8), Mozilla Thunderbird (version up to 78.1), Mozilla Firefox (version up to 79).
CVE-2020-6514 has a severity rating of high, with a severity score of 7.
To fix CVE-2020-6514, you should update your software to the latest available version provided by the vendor.
You can find more information about CVE-2020-6514 in the following references: [1] [2] [3].