PT-2021-2415 · Mozilla+8 · Firefox For Android+10

Felix Weinrank

+1

·

Published

2021-01-05

·

Updated

2024-12-12

·

CVE-2020-16044

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Google Chrome versions prior to 88.0.4324.96 Mozilla Firefox versions prior to 84.0.2 Firefox ESR versions prior to 84.0.2 Firefox for Android versions prior to 84.0.2
Description: The issue is related to a use-after-free vulnerability in the WebRTC implementation, specifically in the COOKIE-ECHO extension. This vulnerability can be exploited by a remote attacker using a crafted SCTP packet, potentially leading to heap corruption or arbitrary code execution. The vulnerability is caused by accessing memory after it has been freed in the COOKIE-ECHO handler.
Recommendations: For Google Chrome versions prior to 88.0.4324.96, update to version 88.0.4324.96 or later. For Mozilla Firefox versions prior to 84.0.2, update to version 84.0.2 or later. For Firefox ESR versions prior to 84.0.2, update to version 84.0.2 or later. For Firefox for Android versions prior to 84.0.2, update to version 84.0.2 or later. As a temporary workaround, consider disabling WebRTC until a patch is available. Restrict access to the COOKIE-ECHO extension to minimize the risk of exploitation. Avoid using the COOKIE-ECHO handler in the affected SCTP packet until the issue is resolved.

Exploit

Fix

Use After Free

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1007
ALT-PU-2021-1008
ALT-PU-2021-1026
ALT-PU-2021-1146
ALT-PU-2021-1151
ALT-PU-2021-1179
ALT-PU-2021-1198
ALT-PU-2021-1200
ALT-PU-2021-1210
ALT-PU-2021-1368
ALT-PU-2021-1369
ALT-PU-2021-1379
ALT-PU-2021-3368
ALT-PU-2022-1782
BDU:2021-01665
CESA-2021_0052
CESA-2021_0053
CESA-2021_0087
CESA-2021_0089
CVE-2020-16044
DLA-2521-1
DLA-2541-1
DSA-4827-1
DSA-4842-1
DSA-4846-1
MGASA-2021-0012
MGASA-2021-0027
MGASA-2021-0406
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2021:0056-1
OPENSUSE-SU-2021:0063-1
OPENSUSE-SU-2021:0093-1
OPENSUSE-SU-2021:0127-1
OPENSUSE-SU-2021:0166-1
OPENSUSE-SU-2021:0173-1
OPENSUSE-SU-2021:0177-1
OPENSUSE-SU-2021:0186-1
OPENSUSE-SU-2021:0973-1
OPENSUSE-SU-2021:1016-1
OPENSUSE-SU-2021_0056-1
OPENSUSE-SU-2021_0063-1
OPENSUSE-SU-2021_0093-1
OPENSUSE-SU-2021_0127-1
OPENSUSE-SU-2021_0166-1
OPENSUSE-SU-2021_0173-1
OPENSUSE-SU-2021_0973-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:10977-1
OPENSUSE-SU-2024:12948-1
OPENSUSE-SU-2024:14572-1
RHSA-2021:0052
RHSA-2021:0053
RHSA-2021:0054
RHSA-2021:0055
RHSA-2021:0087
RHSA-2021:0088
RHSA-2021:0089
RHSA-2021:0160
RHSA-2021_0052
RHSA-2021_0053
RHSA-2021_0087
RHSA-2021_0089
SUSE-SU-2021:0071-1
SUSE-SU-2021:0072-1
SUSE-SU-2021:0080-1
SUSE-SU-2021:0122-1
SUSE-SU-2021:0123-1
SUSE-SU-2021:14595-1
SUSE-SU-2021_0071-1
SUSE-SU-2021_0072-1
SUSE-SU-2021_0080-1
SUSE-SU-2021_14595-1
USN-4687-1
USN-4701-1

Affected Products

Alt Linux
Astra Linux
Centos
Firefox Esr
Firefox For Android
Google Chrome
Linuxmint
Firefox
Red Hat
Suse
Ubuntu