Описание
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| firefox | fixed | 83.0-1 | package | |
| firefox-esr | fixed | 78.5.0esr-1 | package | |
| thunderbird | fixed | 1:78.5.0-1 | package | |
| chromium | fixed | 87.0.4280.88-0.1 | package | |
| chromium | end-of-life | stretch | package |
Примечания
https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/#CVE-2020-16012
https://www.mozilla.org/en-US/security/advisories/mfsa2020-51/#CVE-2020-16012
https://www.mozilla.org/en-US/security/advisories/mfsa2020-52/#CVE-2020-16012
EPSS
Связанные уязвимости
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Уязвимость программных средств Google Chrome, Firefox, Firefox ESR, Thunderbird, связанная с ошибкой подтверждения источника данных, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS