First published: Tue Dec 15 2020(Updated: )
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <78.6 | 78.6 |
Firefox | <84.0 | |
Firefox ESR | <78.6.0 | |
Thunderbird | <78.6.0 | |
Firefox | <84 | 84 |
Firefox ESR | <78.6 | 78.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2020-26973 is categorized as moderate.
To fix CVE-2020-26973, update to Mozilla Firefox version 85 or later.
CVE-2020-26973 affects Mozilla Firefox versions prior to 85, Firefox ESR versions prior to 78.6, and Thunderbird versions prior to 78.6.
Yes, CVE-2020-26973 can potentially be exploited remotely through crafted input.
CVE-2020-26973 is a sanitizer bypass vulnerability that confuses the CSS Sanitizer, leading to incorrect components being removed.