FreeBSD : chromium -- multiple vulnerabilities (9a447f78-d0f8-11ea-9837-e09467587c17)

high Nessus Plugin ID 139110

Language:

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Chrome Releases reports :

This update contains 8 security fixes, including :

- [1105318] High CVE-2020-6537: Type Confusion in V8. Reported by Alphalaab on 2020-07-14

- [1096677] High CVE-2020-6538: Inappropriate implementation in WebView. Reported by Yongke Wang(@Rudykewang) and Aryb1n(@aryb1n) of Tencent Security Xuanwu Lab on 2020-06-18

- [1104061] High CVE-2020-6532: Use after free in SCTP. Reported by Anonymous on 2020-07-09

- [1105635] High CVE-2020-6539: Use after free in CSS. Reported by Oriol Brufau on 2020-07-14

- [1105720] High CVE-2020-6540: Heap buffer overflow in Skia. Reported by Zhen Zhou of NSFOCUS Security Team on 2020-07-15

- [1106773] High CVE-2020-6541: Use after free in WebUSB. Reported by Sergei Glazunov of Google Project Zero on 2020-07-17

Solution

Update the affected package.

See Also

http://www.nessus.org/u?356bbf62

http://www.nessus.org/u?4108ee6e

Plugin Details

Severity: High

ID: 139110

File Name: freebsd_pkg_9a447f78d0f811ea9837e09467587c17.nasl

Version: 1.5

Type: local

Published: 7/30/2020

Updated: 2/27/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-6541

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:chromium, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/28/2020

Vulnerability Publication Date: 7/27/2020

Reference Information

CVE: CVE-2020-6532, CVE-2020-6537, CVE-2020-6538, CVE-2020-6539, CVE-2020-6540, CVE-2020-6541