PT-2019-4860 · Google+3 · Google Chrome+3

Published

2019-11-29

·

Updated

2024-06-15

·

CVE-2020-6379

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 79.0.3945.130
Description The issue is related to a use after free error in the V8 component of Google Chrome, which can be exploited by a remote attacker via a crafted HTML page, potentially leading to heap corruption. This could allow an attacker to access confidential data, compromise data integrity, or cause a denial of service.
Recommendations For versions prior to 79.0.3945.130, update to version 79.0.3945.130 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted HTML pages that could trigger the use after free error in the V8 component until a patch is applied.

Fix

Use After Free

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1129
ALT-PU-2020-1171
ALT-PU-2020-1707
ALT-PU-2020-2441
BDU:2020-01444
BDU:2021-01062
CVE-2020-6379
DSA-4606-1
MGASA-2020-0078
OPENSUSE-SU-2020:0093-1
OPENSUSE-SU-2020_0093-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2020:0214
RHSA-2020_0214

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse