PT-2020-4295 · Mozilla+3 · Firefox+3
Brian Carpenter
·
Published
2020-09-22
·
Updated
2024-12-12
·
CVE-2020-15675
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Firefox versions prior to 81
Description:
The issue is related to the processing of surfaces, where the lifetime may outlive a persistent buffer, leading to memory corruption and a potentially exploitable crash. It is also associated with a WebGL component vulnerability that involves copying a buffer without checking the size of the input data, potentially allowing a remote attacker to execute arbitrary code.
Recommendations:
For versions prior to 81, update to version 81 or later to resolve the issue. As a temporary workaround, consider disabling the WebGL component until a patch is available. Restrict access to potentially vulnerable web pages to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox
Linuxmint
Ubuntu