HIGH8.8
GHSA-m7mf-48hp-5qmr
Inappropriate implementation in V8
Quick fix
GHSA-m7mf-48hp-5qmr — CefSharp.Common: upgrade to the fixed version with the command below.
dotnet add package CefSharp.Common --version 86.0.241Details
CVE-2020-16009: Inappropriate implementation in V8
- https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16009
Google is aware of reports that exploits for CVE-2020-16009 exist in the wild.
Allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
There is currently little to no public information on the issue other than it has been flagged as `High` severity.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/CefSharp.Common
Introduced in:
0Fixed in: 86.0.241Fix
dotnet add package CefSharp.Common --version 86.0.241NuGet/CefSharp.Wpf
Introduced in:
0Fixed in: 86.0.241Fix
dotnet add package CefSharp.Wpf --version 86.0.241NuGet/CefSharp.WinForms
Introduced in:
0Fixed in: 86.0.241Fix
dotnet add package CefSharp.WinForms --version 86.0.241NuGet/CefSharp.Wpf.HwndHost
Introduced in:
0Fixed in: 86.0.241Fix
dotnet add package CefSharp.Wpf.HwndHost --version 86.0.241References
- https://github.com/cefsharp/CefSharp/security/advisories/GHSA-m7mf-48hp-5qmr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-16009[ADVISORY]
- https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html[WEB]
- https://crbug.com/1143772[WEB]
- https://github.com/cefsharp/CefSharp[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S4XYJ7B6OXHZNYSA5J3DBUOFEC6WCAGW[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SC3U3H6AISVZB5PLZLLNF4HMQ4UFFL7M[WEB]
- https://security.gentoo.org/glsa/202011-12[WEB]
- https://www.debian.org/security/2021/dsa-4824[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00017.html[WEB]
- http://packetstormsecurity.com/files/159974/Chrome-V8-Turbofan-Type-Confusion.html[WEB]