CVE-2020-15959
Summary
| CVE | CVE-2020-15959 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-21 20:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Application | Chrome | All | All | All | All | |
| Application | Chrome | All | All | All | All | |
| Application | Opensuse | Backports Sle | 15.0 | sp1 | All | All |
| Application | Opensuse | Backports Sle | 15.0 | sp2 | All | All |
| Application | Opensuse | Backports Sle | 15.0 | sp1 | All | All |
| Application | Opensuse | Backports Sle | 15.0 | sp2 | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Operating System | Opensuse | Leap | 15.2 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Operating System | Opensuse | Leap | 15.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2020:1514-1: important: Security update | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:1510-1: important: Security update | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| [SECURITY] Fedora 33 Update: chromium-85.0.4183.121-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| Chrome Releases: Stable Channel Update for Desktop | MISC | chromereleases.googleblog.com | Release Notes, Vendor Advisory |
| 1122684 - chromium - An open-source project to help move the web forward. - Monorail | MISC | crbug.com | Permissions Required, Vendor Advisory |
| Debian -- Security Information -- DSA-4824-1 chromium | DEBIAN | www.debian.org | Third Party Advisory |
| Qt WebEngine: Multiple vulnerabilities (GLSA 202101-30) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| [SECURITY] Fedora 33 Update: chromium-85.0.4183.121-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [security-announce] openSUSE-SU-2020:1713-1: important: Security update | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| [SECURITY] Fedora 31 Update: chromium-85.0.4183.121-1.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 31 Update: chromium-85.0.4183.121-1.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [security-announce] openSUSE-SU-2020:1499-1: important: Security update | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.