First published: Tue Aug 25 2020(Updated: )
Mozilla developers Jason Kratzer, Christian Holler, and Byron Campen reported memory safety bugs present in Firefox 79 and Firefox ESR 78.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <78.2 | 78.2 |
<80 | 80 | |
<78.2 | 78.2 | |
<78.2 | 78.2 | |
All of | ||
Mozilla Firefox | =80 | |
Google Android | ||
Mozilla Firefox | <80.0 | |
Mozilla Firefox | <80.0 | |
Mozilla Firefox ESR | <78.2 | |
Mozilla Thunderbird | <78.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-15670 is a vulnerability in Firefox for Android 79 that allows for memory corruption and potential code execution.
CVE-2020-15670 affects Firefox versions prior to 80 and Thunderbird version 78.2.
CVE-2020-15670 has a severity rating of 8.8 (high).
To fix CVE-2020-15670, update Firefox to version 80 or higher, and Thunderbird to version 78.2 or higher.
You can find more information about CVE-2020-15670 on the Mozilla bugzilla and security advisories pages.