First published: Tue Sep 22 2020(Updated: )
Mozilla developer Jason Kratzer reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 | |
Mozilla Thunderbird | <78.3 | 78.3 |
Mozilla Firefox ESR | <78.3 | 78.3 |
Mozilla Firefox | <81 | 81 |
Mozilla Firefox | <81.0 | |
Mozilla Firefox ESR | <78.3 | |
Mozilla Thunderbird | <78.3 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
openSUSE | =15.1 | |
openSUSE | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-15673 has a high severity level due to the potential for memory corruption leading to arbitrary code execution.
To fix CVE-2020-15673, update to the latest version of Mozilla Firefox, Firefox ESR, or Thunderbird as specified in the remediation instructions.
CVE-2020-15673 affects Firefox versions prior to 81.
CVE-2020-15673 impacts various platforms using affected versions of Firefox, Firefox ESR, and Thunderbird.
There is no public information confirming that CVE-2020-15673 is being actively exploited, but it is recommended to apply patches to mitigate risks.