PT-2020-5787 · Google+6 · Google Chrome+6
Natashenka
·
Published
2020-07-14
·
Updated
2025-09-29
·
CVE-2020-6514
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Google Chrome versions prior to 84.0.4147.89
Description:
The issue is related to an inappropriate implementation in WebRTC, which can lead to heap corruption via a crafted SCTP stream. This can potentially be exploited by an attacker in a privileged network position. The vulnerability is also related to a buffer overflow in the WebRTC implementation, which can allow a remote attacker to compromise data integrity.
Recommendations:
For Google Chrome versions prior to 84.0.4147.89, update to version 84.0.4147.89 or later to resolve the issue. As a temporary workaround, consider restricting access to WebRTC functionality until the update is applied.
Exploit
Fix
DoS
Information Disclosure
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Google Chrome
Linuxmint
Red Hat
Suse
Ubuntu