First published: Thu Sep 03 2020(Updated: )
A use-after-free bug in the usersctp library was reported upstream. We assume this could have led to memory corruption and a potentially exploitable crash.
Credit: an anonymous researcher an anonymous researcher chrome-cve-admin@google.com an anonymous researcher an anonymous researcher an anonymous researcher Anonymous
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 | |
debian/firefox | 121.0-2 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.6.0esr-1~deb10u1 102.15.0esr-1~deb11u1 115.6.0esr-1~deb11u1 115.5.0esr-1~deb12u1 115.6.0esr-1~deb12u1 115.6.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.6.0-1~deb10u1 1:102.13.1-1~deb11u1 1:115.6.0-1~deb11u1 1:115.5.0-1~deb12u1 1:115.6.0-1~deb12u1 1:115.6.0-1 | |
Mozilla Firefox ESR | <78.4 | 78.4 |
Mozilla Thunderbird | <78.4 | 78.4 |
Mozilla Firefox | <82 | 82 |
tvOS | <14.3 | 14.3 |
Google Chrome | <86.0.4240.75 | 86.0.4240.75 |
Apple macOS | <11.1 | 11.1 |
macOS Catalina | ||
macOS Mojave | ||
Apple Mobile Safari | <14.0.2 | 14.0.2 |
Apple iOS, iPadOS, and watchOS | <14.3 | 14.3 |
Apple iOS, iPadOS, and watchOS | <14.3 | 14.3 |
Apple iOS, iPadOS, and watchOS | <7.2 | 7.2 |
Google Chrome | <86.0.4240.75 | |
Debian | =10.0 | |
Fedora | =31 | |
Fedora | =32 | |
Fedora | =33 | |
openSUSE Backports | =15.0-sp2 | |
Apple Mobile Safari | <14.0.2 | |
Apple iOS, iPadOS, and watchOS | <14.3 | |
iOS | <14.3 | |
Apple iOS and macOS | <11.1 | |
tvOS | <14.3 | |
Apple iOS, iPadOS, and watchOS | <7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-15969 is a use-after-free issue in the WebRTC usersctp library.
CVE-2020-15969 has a severity rating of high (7).
CVE-2020-15969 affects Apple macOS Big Sur (up to version 11.1), Apple Catalina, Apple Mojave, Mozilla Firefox (up to version 82), Apple iOS (up to version 14.3), Apple iPadOS (up to version 14.3), Apple Safari (up to version 14.0.2), Apple watchOS (up to version 7.2), Apple tvOS (up to version 14.3), Mozilla Thunderbird (up to version 78.4), and Mozilla Firefox ESR (up to version 78.4).
To fix CVE-2020-15969, users should update their affected software to the latest available version provided by the respective vendors.
You can find more information about CVE-2020-15969 on the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1666570), [usrsctp Commit](https://github.com/sctplab/usrsctp/commit/ffed0925f27d404173c1e3e750d818f432d2c019), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/).