PT-2020-14576 · Mozilla+1 · Firefox+1

Crixer

·

Published

2020-08-25

·

Updated

2024-12-12

·

CVE-2020-15667

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 80
Description A heap overflow could occur when processing a MAR update file after the signature has been validated, due to an invalid name length. This could lead to memory corruption and potentially arbitrary code execution. The issue is only exploitable with the Mozilla-controlled signing key in Firefox as released by Mozilla.
Recommendations For versions prior to 80, update to version 80 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2706
ALT-PU-2020-3442
ALT-PU-2021-2725
ALT-PU-2021-2881
ALT-PU-2021-3368
ALT-PU-2021-3369
ALT-PU-2022-1781
CVE-2020-15667
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox