PT-2020-2005 · Mozilla+5 · Firefox+7

Francisco Alonso

+2

·

Published

2020-04-03

·

Updated

2024-12-12

·

CVE-2020-6820

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 74.0.1 Firefox ESR versions prior to 68.6.1 Thunderbird versions prior to 68.7.0
Description The issue is related to a use-after-free condition in the ReadableStream component, potentially allowing a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. There have been targeted attacks in the wild exploiting this flaw.
Recommendations For Firefox versions prior to 74.0.1, update to version 74.0.1 or later. For Firefox ESR versions prior to 68.6.1, update to version 68.6.1 or later. For Thunderbird versions prior to 68.7.0, update to version 68.7.0 or later.

Exploit

Fix

Double Free

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1664
ALT-PU-2020-1674
ALT-PU-2020-1701
ALT-PU-2020-1756
ALT-PU-2020-1760
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-3368
BDU:2020-01393
CESA-2020_1339
CESA-2020_1341
CESA-2020_1488
CESA-2020_1489
CESA-2020_1495
CVE-2020-6820
DLA-2170-1
DLA-2172-1
DSA-4653-1
DSA-4656-1
ELSA-2020-1338
ELSA-2020-1339
ELSA-2020-1341
ELSA-2020-1488
ELSA-2020-1489
ELSA-2020-1495
MGASA-2020-0161
MGASA-2020-0170
OPENSUSE-SU-2020:0461-1
OPENSUSE-SU-2020:0520-1
OPENSUSE-SU-2020:0544-1
OPENSUSE-SU-2020_0461-1
OPENSUSE-SU-2020_0520-1
OPENSUSE-SU-2020_0544-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:1338
RHSA-2020:1339
RHSA-2020:1340
RHSA-2020:1341
RHSA-2020:1488
RHSA-2020:1489
RHSA-2020:1495
RHSA-2020:1496
RHSA-2020_1338
RHSA-2020_1339
RHSA-2020_1341
RHSA-2020_1488
RHSA-2020_1489
RHSA-2020_1495
SUSE-SU-2020:0928-1
SUSE-SU-2020:0929-1
SUSE-SU-2020:1027-1
SUSE-SU-2020:14337-1
USN-4317-1
USN-4328-1
USN-4335-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu