Vulnerability CVE-2020-16012: Information

Description

Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Published: Jan. 8, 2021
Modified: Jan. 12, 2021

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus87.0.4280.66-alt1126.0.6478.55-alt1ALT-PU-2020-3409-1262409Fixed
chromiump1087.0.4280.66-alt1119.0.6045.159-alt0.p10.1ALT-PU-2020-3409-1262409Fixed
chromiump987.0.4280.141-alt0.1.p997.0.4692.99-alt0.p9.1ALT-PU-2021-1157-1264552Fixed
chromiumc10f187.0.4280.66-alt1110.0.5481.177-alt1.p10.1ALT-PU-2020-3409-1262409Fixed
chromiump1187.0.4280.66-alt1125.0.6422.141-alt1ALT-PU-2020-3409-1262409Fixed
chromium-gostsisyphus87.0.4280.141-alt1125.0.6422.112-alt1ALT-PU-2021-1049-1264758Fixed
chromium-gostp1087.0.4280.141-alt1110.0.5481.177-alt1.p10.1ALT-PU-2021-1049-1264758Fixed
chromium-gostp988.0.4324.96-alt0.1.p996.0.4664.45-alt2.p9.1ALT-PU-2021-1210-1265329Fixed
chromium-gostc10f187.0.4280.141-alt1110.0.5481.177-alt1.p10.1ALT-PU-2021-1049-1264758Fixed
chromium-gostc9f288.0.4324.150-alt0.1.c996.0.4664.45-alt2.c9.1ALT-PU-2021-1379-1265372Fixed
chromium-gostp1187.0.4280.141-alt1124.0.6367.78-alt1ALT-PU-2021-1049-1264758Fixed
firefoxsisyphus83.0-alt1127.0-alt1ALT-PU-2020-3384-1261953Fixed
firefoxp1083.0-alt1118.0.2-alt0.p10.1ALT-PU-2020-3384-1261953Fixed
firefoxp993.0-alt0.p9.1105.0.1-alt0.c9.1ALT-PU-2022-1782-1288073Fixed
firefoxc10f183.0-alt1112.0.2-alt0.p10.1ALT-PU-2020-3384-1261953Fixed
firefoxc9f293.0-alt0.p9.1105.0.1-alt0.c9.1ALT-PU-2021-3368-1288792Fixed
firefoxp1183.0-alt1126.0.1-alt1ALT-PU-2020-3384-1261953Fixed
firefox-esrsisyphus78.5.0-alt1115.11.0-alt1ALT-PU-2020-3340-1261946Fixed
firefox-esrp1091.1.0-alt1115.11.0-alt1ALT-PU-2021-2881-1284980Fixed
firefox-esrp978.5.0-alt0.1.p9102.11.0-alt0.c9.1ALT-PU-2020-3379-1261955Fixed
firefox-esrc10f191.1.0-alt1115.9.1-alt0.c10.1ALT-PU-2021-2881-1284980Fixed
firefox-esrc9f291.3.0-alt1.c9.1102.12.0-alt0.c9.1ALT-PU-2021-3369-1288792Fixed
firefox-esrp1178.5.0-alt1115.11.0-alt1ALT-PU-2020-3340-1261946Fixed
thunderbirdsisyphus78.5.0-alt1115.9.0-alt1ALT-PU-2020-3386-1262148Fixed
thunderbirdp1078.5.0-alt1115.9.0-alt1ALT-PU-2020-3386-1262148Fixed
thunderbirdp978.5.0-alt0.1.p9102.11.0-alt0.c9.1ALT-PU-2020-3424-1262218Fixed
thunderbirdc10f178.5.0-alt1115.9.0-alt0.c10.1ALT-PU-2020-3386-1262148Fixed
thunderbirdc9f278.7.0-alt0.1.c9102.11.0-alt0.c9.1ALT-PU-2021-1369-1264611Fixed
thunderbirdp1178.5.0-alt1115.9.0-alt1ALT-PU-2020-3386-1262148Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_17.html
  • Release Notes
  • Vendor Advisory
https://crbug.com/1088224
  • Exploit
  • Issue Tracking
  • Patch
  • Vendor Advisory
    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      83.0

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excliding
      87.0.4280.66