First published: Tue Dec 15 2020(Updated: )
Mozilla developers Christian Holler, Jan-Ivar Bruaroey, and Gabriele Svelto reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <84 | 84 |
Firefox | <84.0 |
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1607449%2C1640416%2C1656459%2C1669914%2C1673567
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-35114 is classified as a high severity vulnerability due to its potential to lead to memory corruption and possibly allow arbitrary code execution.
To remediate CVE-2020-35114, update Mozilla Firefox to version 84 or higher.
CVE-2020-35114 affects Mozilla Firefox versions prior to 84.
Yes, CVE-2020-35114 could potentially be exploited remotely if attackers leverage the memory safety bugs.
CVE-2020-35114 is associated with memory safety bugs that may lead to memory corruption issues.