PT-2020-3495 · Mozilla+6 · Firefox+8

Alexandru Michis

+6

·

Published

2020-05-05

·

Updated

2024-12-12

·

CVE-2020-12395

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox ESR versions 68.7 through 68.7 Firefox versions 75 through 75 Thunderbird versions prior to 68.8.0
Description The issue is related to memory safety bugs, which can lead to memory corruption. With sufficient effort, these bugs could potentially be exploited to run arbitrary code. The vulnerability is also described as a buffer overflow in memory, which could allow a remote attacker to cause a denial of service.
Recommendations For Firefox ESR version 68.7, update to version 68.8 or later. For Firefox version 75, update to version 76 or later. For Thunderbird versions prior to 68.8.0, update to version 68.8.0 or later.

Exploit

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1915
ALT-PU-2020-1916
ALT-PU-2020-1932
ALT-PU-2020-1933
ALT-PU-2020-1943
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-3368
BDU:2020-03821
CESA-2020_2031
CESA-2020_2036
CESA-2020_2037
CESA-2020_2046
CESA-2020_2049
CESA-2020_2050
CVE-2020-12395
DLA-2205-1
DLA-2206-1
DSA-4678-1
DSA-4683-1
MGASA-2020-0208
MGASA-2020-0209
OPENSUSE-SU-2020:0621-1
OPENSUSE-SU-2020:0643-1
OPENSUSE-SU-2020_0621-1
OPENSUSE-SU-2020_0643-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:2031
RHSA-2020:2032
RHSA-2020:2033
RHSA-2020:2036
RHSA-2020:2037
RHSA-2020:2046
RHSA-2020:2047
RHSA-2020:2048
RHSA-2020:2049
RHSA-2020:2050
RHSA-2020_2031
RHSA-2020_2036
RHSA-2020_2037
RHSA-2020_2046
RHSA-2020_2049
RHSA-2020_2050
SUSE-SU-2020:1209-1
SUSE-SU-2020:1218-1
SUSE-SU-2020:1225-1
SUSE-SU-2020:14359-1
USN-4353-1
USN-4353-2
USN-4373-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Suse
Thunderbird
Ubuntu