PT-2020-4295 · Mozilla+3 · Firefox+3

Brian Carpenter

·

Published

2020-09-22

·

Updated

2024-12-12

·

CVE-2020-15675

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 81
Description: The issue is related to the processing of surfaces, where the lifetime may outlive a persistent buffer, leading to memory corruption and a potentially exploitable crash. It is also associated with a WebGL component vulnerability that involves copying a buffer without checking the size of the input data, potentially allowing a remote attacker to execute arbitrary code.
Recommendations: For versions prior to 81, update to version 81 or later to resolve the issue. As a temporary workaround, consider disabling the WebGL component until a patch is available. Restrict access to potentially vulnerable web pages to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2889
ALT-PU-2021-1152
ALT-PU-2021-2725
ALT-PU-2021-2881
ALT-PU-2021-3368
ALT-PU-2021-3369
ALT-PU-2022-1781
BDU:2020-04788
CVE-2020-15675
OESA-2023-1673
OESA-2023-1674
OESA-2024-1859
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-4546-1
USN-4546-2

Affected Products

Alt Linux
Firefox
Linuxmint
Ubuntu