4.3
CVE-2020-6571
- EPSS 1.31%
- Veröffentlicht 21.09.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:35:59
- Erkennungen
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse ≫ Backports Sle Version 15.0 Update sp1
Opensuse ≫ Backports Sle Version 15.0 Update sp2
Fedoraproject ≫ Fedora Version 33
Debian ≫ Debian Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.31% | 0.668 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.debian.org/security/2021/dsa-4824
https://security.gentoo.org/glsa/202101-30
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00072.html
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00078.html
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00081.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EE7XWIZBME7JAY7N6CGPET4CLNHHEIVT/
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html
https://crbug.com/1085315