PT-2020-14576 · Mozilla+1 · Firefox+1
Crixer
·
Published
2020-08-25
·
Updated
2024-12-12
·
CVE-2020-15667
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 80
Description
A heap overflow could occur when processing a MAR update file after the signature has been validated, due to an invalid name length. This could lead to memory corruption and potentially arbitrary code execution. The issue is only exploitable with the Mozilla-controlled signing key in Firefox as released by Mozilla.
Recommendations
For versions prior to 80, update to version 80 or later to resolve the issue.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox