PT-2020-4559 · Google+3 · Google Chrome+3
Published
2020-11-02
·
Updated
2024-06-15
·
CVE-2020-16008
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 86.0.4240.183
Description
The issue is a stack buffer overflow in WebRTC, which could allow a remote attacker to exploit stack corruption via a crafted WebRTC packet. This could potentially impact the confidentiality, integrity, and availability of protected information.
Recommendations
For versions prior to 86.0.4240.183, update to version 86.0.4240.183 or later to resolve the issue. As a temporary workaround, consider disabling WebRTC functionality until a patch is applied. Restrict access to WebRTC packets to minimize the risk of exploitation. Avoid using crafted WebRTC packets in affected API endpoints until the issue is resolved.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Red Hat
Suse