QID 982958

QID 982958: Dotnet (nuget) Security Update for CefSharp.Wpf.HwndHost (GHSA-pv36-h7jh-qm62)

Security update has been released for CefSharp.WinForms,CefSharp.Wpf.HwndHost,CefSharp.Wpf,CefSharp.Common to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

A memory corruption bug(Heap overflow) in the FreeType font rendering library.

> This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .

As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/

Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Upgrade to 85.3.130 or higher
    Vendor References

    CVEs related to QID 982958

    Software Advisories
    Advisory ID Software Component Link
    GHSA-pv36-h7jh-qm62 CefSharp.Common URL Logo github.com/advisories/GHSA-pv36-h7jh-qm62
    GHSA-pv36-h7jh-qm62 CefSharp.WinForms URL Logo github.com/advisories/GHSA-pv36-h7jh-qm62
    GHSA-pv36-h7jh-qm62 CefSharp.Wpf URL Logo github.com/advisories/GHSA-pv36-h7jh-qm62
    GHSA-pv36-h7jh-qm62 CefSharp.Wpf.HwndHost URL Logo github.com/advisories/GHSA-pv36-h7jh-qm62