First published: Thu Sep 03 2020(Updated: )
A use-after-free bug in the usersctp library was reported upstream. We assume this could have led to memory corruption and a potentially exploitable crash.
Credit: an anonymous researcher an anonymous researcher chrome-cve-admin@google.com an anonymous researcher an anonymous researcher an anonymous researcher Anonymous
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <14.0.2 | 14.0.2 |
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 | |
debian/firefox | 121.0-2 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.6.0esr-1~deb10u1 102.15.0esr-1~deb11u1 115.6.0esr-1~deb11u1 115.5.0esr-1~deb12u1 115.6.0esr-1~deb12u1 115.6.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.6.0-1~deb10u1 1:102.13.1-1~deb11u1 1:115.6.0-1~deb11u1 1:115.5.0-1~deb12u1 1:115.6.0-1~deb12u1 1:115.6.0-1 | |
Apple macOS Big Sur | <11.1 | 11.1 |
Apple Catalina | ||
Apple Mojave | ||
Google Chrome | <86.0.4240.75 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
openSUSE Backports SLE | =15.0-sp2 | |
Apple Safari | <14.0.2 | |
Apple iPadOS | <14.3 | |
Apple iPhone OS | <14.3 | |
Apple macOS | <11.1 | |
Apple tvOS | <14.3 | |
Apple watchOS | <7.2 | |
Apple watchOS | <7.2 | 7.2 |
Apple tvOS | <14.3 | 14.3 |
Mozilla Firefox ESR | <78.4 | 78.4 |
Mozilla Thunderbird | <78.4 | 78.4 |
Mozilla Firefox | <82 | 82 |
Apple iOS | <14.3 | 14.3 |
Apple iPadOS | <14.3 | 14.3 |
Google Chrome | <86.0.4240.75 | 86.0.4240.75 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-15969 is a use-after-free issue in the WebRTC usersctp library.
CVE-2020-15969 has a severity rating of high (7).
CVE-2020-15969 affects Apple macOS Big Sur (up to version 11.1), Apple Catalina, Apple Mojave, Mozilla Firefox (up to version 82), Apple iOS (up to version 14.3), Apple iPadOS (up to version 14.3), Apple Safari (up to version 14.0.2), Apple watchOS (up to version 7.2), Apple tvOS (up to version 14.3), Mozilla Thunderbird (up to version 78.4), and Mozilla Firefox ESR (up to version 78.4).
To fix CVE-2020-15969, users should update their affected software to the latest available version provided by the respective vendors.
You can find more information about CVE-2020-15969 on the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1666570), [usrsctp Commit](https://github.com/sctplab/usrsctp/commit/ffed0925f27d404173c1e3e750d818f432d2c019), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/).