First published: Tue Dec 15 2020(Updated: )
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <84 | 84 |
<84 | 84 | |
<78.6 | 78.6 | |
<78.6 | 78.6 | |
Mozilla Firefox | <84.0 | |
Mozilla Firefox ESR | <78.6.0 | |
Mozilla Thunderbird | <78.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-26971 is a vulnerability in certain video drivers in Mozilla Firefox, Thunderbird, and Firefox ESR that can lead to a heap buffer overflow.
CVE-2020-26971 occurs when certain blit values provided by the user are not properly constrained, resulting in a heap buffer overflow.
Mozilla Firefox versions up to 84, Thunderbird versions up to 78.6, and Firefox ESR versions up to 78.6 are affected by CVE-2020-26971.
CVE-2020-26971 has a severity rating of high with a value of 7.
To fix CVE-2020-26971, update Mozilla Firefox to version 84, Thunderbird to version 78.6, or Firefox ESR to version 78.6.