PT-2020-6726 · Mozilla+4 · Thunderbird+5

Jason Kratzer

·

Published

2019-09-13

·

Updated

2024-06-15

·

CVE-2020-15669

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox ESR versions prior to 68.12 Thunderbird versions prior to 68.12
Description The issue is related to a use-after-free error, which occurs when memory is accessed after it has been freed. This could potentially allow a remote attacker to execute arbitrary code by using a specially crafted web page. The error happens when an operation, such as a fetch, is aborted, and an abort signal is deleted while notifying objects, resulting in a use-after-free situation.
Recommendations For Firefox ESR versions prior to 68.12, update to version 68.12 or later. For Thunderbird versions prior to 68.12, update to version 68.12 or later.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2686
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2709
ALT-PU-2020-2933
ALT-PU-2020-2934
ALT-PU-2021-1368
ALT-PU-2021-1369
BDU:2022-05802
CESA-2020_3556
CESA-2020_3557
CESA-2020_3558
CESA-2020_3631
CESA-2020_3634
CESA-2020_3643
CVE-2020-15669
DLA-2346-1
DLA-2360-1
DSA-4749-1
DSA-4754-1
MGASA-2020-0348
MGASA-2020-0352
OPENSUSE-SU-2020:1383-1
OPENSUSE-SU-2020:1392-1
OPENSUSE-SU-2020_1383-1
OPENSUSE-SU-2020_1392-1
OPENSUSE-SU-2024:10601-1
RHSA-2020:3555
RHSA-2020:3556
RHSA-2020:3557
RHSA-2020:3558
RHSA-2020:3559
RHSA-2020:3631
RHSA-2020:3632
RHSA-2020:3633
RHSA-2020:3634
RHSA-2020:3643
RHSA-2020_3556
RHSA-2020_3557
RHSA-2020_3558
RHSA-2020_3631
RHSA-2020_3634
RHSA-2020_3643
SUSE-SU-2020:2552-1

Affected Products

Alt Linux
Centos
Firefox Esr
Red Hat
Suse
Thunderbird