CVE Published: 04/05/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: Google |
Vendor: Google LLC |
Product: Google Earth Pro Status : PUBLISHED
CVE-2020-8896 Description
A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted key to read data past the end of the buffer used to hold it. Mitigation: Update to Google Earth Pro 7.3.3.
Metrics
CVSS Version: 3.1 |
Base Score: 4.2 MEDIUM Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L