PT-2020-3518 · Mozilla+7 · Firefox+9
Natalie Silvanovich
·
Published
2020-05-05
·
Updated
2024-12-12
·
CVE-2020-6831
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 76
Firefox ESR versions prior to 68.8
Thunderbird versions prior to 68.8.0
Description
The issue is related to a buffer overflow that could occur when parsing and validating SCTP chunks in WebRTC, potentially leading to memory corruption and a crash. This could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations
For Firefox versions prior to 76, update to version 76 or later to resolve the issue.
For Firefox ESR versions prior to 68.8, update to version 68.8 or later to resolve the issue.
For Thunderbird versions prior to 68.8.0, update to version 68.8.0 or later to resolve the issue.
Exploit
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Firefox
Firefox Esr
Google Chrome
Linuxmint
Red Hat
Suse
Thunderbird
Ubuntu