Show plain JSON{"affected_release": [{"advisory": "RHSA-2020:5561", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "firefox-0:78.6.0-1.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2020-12-16T00:00:00Z"}, {"advisory": "RHSA-2020:5618", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "thunderbird-0:78.6.0-1.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2020-12-17T00:00:00Z"}, {"advisory": "RHSA-2020:5562", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "firefox-0:78.6.0-1.el8_3", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2020-12-16T00:00:00Z"}, {"advisory": "RHSA-2020:5624", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "thunderbird-0:78.6.0-1.el8_3", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2020-12-17T00:00:00Z"}, {"advisory": "RHSA-2020:5565", "cpe": "cpe:/a:redhat:rhel_e4s:8.0", "package": "firefox-0:78.6.0-1.el8_0", "product_name": "Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions", "release_date": "2020-12-16T00:00:00Z"}, {"advisory": "RHSA-2020:5645", "cpe": "cpe:/a:redhat:rhel_e4s:8.0", "package": "thunderbird-0:78.6.0-1.el8_0", "product_name": "Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions", "release_date": "2020-12-21T00:00:00Z"}, {"advisory": "RHSA-2020:5564", "cpe": "cpe:/a:redhat:rhel_eus:8.1", "package": "firefox-0:78.6.0-1.el8_1", "product_name": "Red Hat Enterprise Linux 8.1 Extended Update Support", "release_date": "2020-12-16T00:00:00Z"}, {"advisory": "RHSA-2020:5644", "cpe": "cpe:/a:redhat:rhel_eus:8.1", "package": "thunderbird-0:78.6.0-1.el8_1", "product_name": "Red Hat Enterprise Linux 8.1 Extended Update Support", "release_date": "2020-12-21T00:00:00Z"}, {"advisory": "RHSA-2020:5563", "cpe": "cpe:/a:redhat:rhel_eus:8.2", "package": "firefox-0:78.6.0-1.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Extended Update Support", "release_date": "2020-12-16T00:00:00Z"}, {"advisory": "RHSA-2020:5622", "cpe": "cpe:/a:redhat:rhel_eus:8.2", "package": "thunderbird-0:78.6.0-1.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Extended Update Support", "release_date": "2020-12-17T00:00:00Z"}], "bugzilla": {"description": "chromium-browser: Uninitialized Use in V8", "id": "1904515", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1904515"}, "csaw": false, "cvss3": {"cvss3_base_score": "6.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "status": "verified"}, "details": ["Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", "The Mozilla Foundation Security Advisory describes this flaw as:\nWhen a BigInt was right-shifted the backing store was not properly cleared, allowing uninitialized memory to be read."], "name": "CVE-2020-16042", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Out of support scope", "package_name": "thunderbird", "product_name": "Red Hat Enterprise Linux 5"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Out of support scope", "package_name": "firefox", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Out of support scope", "package_name": "thunderbird", "product_name": "Red Hat Enterprise Linux 6"}], "public_date": "2020-12-02T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2020-16042\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-16042\nhttps://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.html"], "threat_severity": "Important"}