First published: Tue Aug 25 2020(Updated: )
When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <80 | 80 |
<80 | 80 | |
Mozilla Firefox | <80.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-15667 is a vulnerability in Mozilla Firefox that could lead to memory corruption and potentially arbitrary code execution.
CVE-2020-15667 occurs when processing a MAR update file after the signature has been validated, where an invalid name length could result in a heap overflow.
Yes, Mozilla Firefox up to version 80.0 is affected by CVE-2020-15667.
CVE-2020-15667 has a high severity rating with a CVSS score of 8.8.
The CWE ID of CVE-2020-15667 is 787.