CVE-2020-12416: Race Condition
Published Jun 30, 2020
·Updated
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash.
Affected Software
6 affected componentsFixes available
Mozilla Firefox<78.0
openSUSE Leap=15.1
openSUSE Leap=15.2
Mozilla Thunderbird<78
78
Mozilla Firefox<78
78
debian/firefox
137.0.2-1
Event History
Jun 30, 2020
CVE Published
12:00 AM
Jul 9, 2020
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:38 PM
Description
Sep 20, 2024
Data Sourced
via Ubuntu·01:15 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:38 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2020-12416?
CVE-2020-12416 is a vulnerability in Firefox and Thunderbird that could result in a use-after-free, memory corruption, and potentially exploitable crash.
2
How does CVE-2020-12416 affect Firefox?
CVE-2020-12416 affects Firefox versions prior to 78.0.
3
How does CVE-2020-12416 affect Thunderbird?
CVE-2020-12416 affects Thunderbird versions prior to 78.0.
4
What is the severity of CVE-2020-12416?
CVE-2020-12416 has a severity level of critical with a CVSS score of 8.8.
5
How do I fix CVE-2020-12416 in Firefox and Thunderbird?
To fix CVE-2020-12416, upgrade to Firefox version 78.0 or later, or upgrade to Thunderbird version 78.0 or later.