PT-2020-6942 · Mozilla+5 · Firefox+5

Thomas Imbert

·

Published

2020-01-20

·

Updated

2024-12-12

·

CVE-2020-6796

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 73 Firefox ESR versions prior to 68.5
Description The issue is related to a buffer overflow, allowing a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. A content process could modify shared memory, leading to an out-of-bounds write, memory corruption, and a potentially exploitable crash.
Recommendations For Firefox versions prior to 73, update to version 73 or later to resolve the issue. For Firefox ESR versions prior to 68.5, update to version 68.5 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1186
ALT-PU-2020-1237
ALT-PU-2020-1399
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-3368
BDU:2023-07822
CESA-2020_0512
CESA-2020_0520
CESA-2020_0521
CVE-2020-6796
DLA-2102-1
DSA-4620-1
MGASA-2020-0090
OPENSUSE-SU-2020:0230-1
OPENSUSE-SU-2020_0230-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:0512
RHSA-2020:0519
RHSA-2020:0520
RHSA-2020:0521
RHSA-2020_0512
RHSA-2020_0520
RHSA-2020_0521
SUSE-SU-2020:0383-1
SUSE-SU-2020:0384-1
SUSE-SU-2020:14290-1
SUSE-SU-2020_0383-1
SUSE-SU-2020_0384-1
SUSE-SU-2020_14290-1
USN-4278-1
USN-4278-2
USN-4278-3

Affected Products

Alt Linux
Centos
Firefox
Red Hat
Suse
Ubuntu