GHSA-pv36-h7jh-qm62
Heap buffer overflow in CefSharp
Quick fix
GHSA-pv36-h7jh-qm62 — CefSharp.Common: upgrade to the fixed version with the command below.
dotnet add package CefSharp.Common --version 85.3.130Details
### Impact A memory corruption bug(Heap overflow) in the FreeType font rendering library.
> This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .
As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.
### Patches Upgrade to 85.3.130 or higher
### References - https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/ - https://www.zdnet.com/article/google-releases-chrome-security-update-to-patch-actively-exploited-zero-day/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999 - https://magpcss.org/ceforum/viewtopic.php?f=10&t=17942
To review the `CEF/Chromium` patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10d
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 85.3.130dotnet add package CefSharp.Common --version 85.3.1300Fixed in: 85.3.130dotnet add package CefSharp.Wpf --version 85.3.1300Fixed in: 85.3.130dotnet add package CefSharp.WinForms --version 85.3.1300Fixed in: 85.3.130dotnet add package CefSharp.Wpf.HwndHost --version 85.3.130References
- https://github.com/cefsharp/CefSharp/security/advisories/GHSA-pv36-h7jh-qm62[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-15999[ADVISORY]
- https://www.nuget.org/packages/CefSharp.Wpf.HwndHost[WEB]
- https://www.nuget.org/packages/CefSharp.Wpf[WEB]
- https://www.nuget.org/packages/CefSharp.WinForms[WEB]
- https://www.nuget.org/packages/CefSharp.Common[WEB]
- https://www.debian.org/security/2021/dsa-4824[WEB]
- https://security.netapp.com/advisory/ntap-20240812-0001[WEB]
- https://security.gentoo.org/glsa/202401-19[WEB]
- https://security.gentoo.org/glsa/202012-04[WEB]
- https://security.gentoo.org/glsa/202011-12[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7[WEB]
- https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.html[WEB]
- https://github.com/cefsharp/CefSharp[PACKAGE]
- https://crbug.com/1139963[WEB]
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html[WEB]
- http://seclists.org/fulldisclosure/2020/Nov/33[WEB]