Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-16044

Опубликовано: 06 янв. 2021
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

Отчет

Regarding Thunderbird: in general this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail, but it is potentially a risk in browser or browser-like contexts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7firefoxFixedRHSA-2021:005311.01.2021
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2021:008713.01.2021
Red Hat Enterprise Linux 8firefoxFixedRHSA-2021:005211.01.2021
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2021:008913.01.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportfirefoxFixedRHSA-2021:005411.01.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportthunderbirdFixedRHSA-2021:016018.01.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportfirefoxFixedRHSA-2021:005511.01.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportthunderbirdFixedRHSA-2021:008813.01.2021

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1913503Mozilla: Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk

EPSS

Процентиль: 59%
0.00379
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 5 лет назад

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

CVSS3: 8.8
nvd
почти 5 лет назад

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

msrc
около 5 лет назад

Chromium CVE-2020-16044: Use after free in WebRTC

CVSS3: 8.8
debian
почти 5 лет назад

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowe ...

suse-cvrf
около 5 лет назад

Security update for MozillaThunderbird

EPSS

Процентиль: 59%
0.00379
Низкий

8.8 High

CVSS3