CVE-2020-6514: Infoleak
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Other sources
WebRTC used the memory address of a class instance as a connection identifier. Unfortunately, this value is often transmitted to the peer, which allows bypassing ASLR.
— Mozilla
WebRTC. A memory corruption issue was addressed with improved state management.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9884
- CVE-2020-9889
- CVE-2020-9888
- CVE-2020-9890
- CVE-2020-9891
- CVE-2020-9907
- CVE-2020-9883
- CVE-2020-9865
- CVE-2020-9900
- CVE-2020-9980
- CVE-2020-9933
- CVE-2020-9914
- CVE-2020-27933
- CVE-2020-11758
- CVE-2020-11759
- CVE-2020-11760
- CVE-2020-11761
- CVE-2020-11762
- CVE-2020-11763
- CVE-2020-11764
- CVE-2020-11765
- CVE-2020-9871
- CVE-2020-9872
- CVE-2020-9874
- CVE-2020-9879
- CVE-2020-9936
- CVE-2020-9937
- CVE-2020-9919
- CVE-2020-9876
- CVE-2020-9873
- CVE-2020-9938
- CVE-2020-9984
- CVE-2020-9877
- CVE-2020-9875
- CVE-2019-14899
- CVE-2020-9909
- CVE-2020-9904
- CVE-2020-9863
- CVE-2020-9892
- CVE-2020-9902
- CVE-2020-9905
- CVE-2020-9926
- CVE-2020-9880
- CVE-2020-9878
- CVE-2020-9940
- CVE-2020-9868
- CVE-2020-9901
- CVE-2020-9894
- CVE-2020-9915
- CVE-2020-9925
- CVE-2020-9893
- CVE-2020-9895
- CVE-2020-9910
- CVE-2020-9916
- CVE-2020-9862
- CVE-2020-6514
- CVE-2020-9918
- CVE-2020-9923
- CVE-2020-9997
- CVE-2020-9920
- CVE-2020-9885
- CVE-2020-9881
- CVE-2020-9882
- CVE-2020-9985
- CVE-2020-9906
- CVE-2020-15652
- CVE-2020-15655
- CVE-2020-15653
- CVE-2020-6463
- CVE-2020-15656
- CVE-2020-15658
- CVE-2020-15657
- CVE-2020-15654
- CVE-2020-15659
- CVE-2020-15650
- CVE-2020-15649
- CVE-2020-9942
- CVE-2020-9912
- CVE-2020-9903
- CVE-2020-9911
- CVE-2020-9931
- CVE-2020-9934
- CVE-2019-19906
- CVE-2020-9898
- CVE-2020-9917
Frequently Asked Questions
What is CVE-2020-6514?
CVE-2020-6514 is a memory corruption issue in WebRTC that allows bypassing ASLR.
What software is affected by CVE-2020-6514?
The affected software includes Mozilla Firefox ESR (version up to 68.11), Apple iOS (version up to 13.6), Apple iPadOS (version up to 13.6), Apple Safari (version up to 13.1.2), Apple watchOS (version up to 6.2.8), Apple tvOS (version up to 13.4.8), Mozilla Thunderbird (version up to 78.1), Mozilla Firefox (version up to 79).
What is the severity of CVE-2020-6514?
CVE-2020-6514 has a severity rating of high, with a severity score of 7.
How can I fix the vulnerability CVE-2020-6514?
To fix CVE-2020-6514, you should update your software to the latest available version provided by the vendor.
Where can I find more information about CVE-2020-6514?
You can find more information about CVE-2020-6514 in the following references: [1] [2] [3].