First published: Tue Aug 25 2020(Updated: )
When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <68.12 | 68.12 |
<68.12 | 68.12 | |
<68.12 | 68.12 | |
Mozilla Firefox ESR | <68.12 | |
Mozilla Thunderbird | <68.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-15669 is a vulnerability that allows for a use-after-free attack when aborting an operation like a fetch in Firefox ESR < 68.12 and Thunderbird < 68.12.
CVE-2020-15669 has a severity score of 8.8 (high).
CVE-2020-15669 affects Firefox ESR versions earlier than 68.12 and Thunderbird versions earlier than 68.12.
CVE-2020-15669 can be exploited with enough effort to run arbitrary code.
To mitigate CVE-2020-15669, update to Firefox ESR version 68.12 or higher or Thunderbird version 68.12 or higher.