CVE-2020-6796: High severity Mozilla Firefox ESR vulnerability
A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially exploitable crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 68.5 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 73 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0.6-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.12.0esr-1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 73 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 68.5
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6796?
CVE-2020-6796 is a vulnerability in Firefox that allows a content process to modify shared memory relating to crash reporting information, potentially causing memory corruption and a potentially exploitable crash.
Which versions of Firefox are affected by CVE-2020-6796?
Firefox versions prior to 73 and Firefox ESR versions prior to 68.5 are affected by CVE-2020-6796.
What is the severity of CVE-2020-6796?
CVE-2020-6796 has a severity rating of 8.8 (high).
How can I fix CVE-2020-6796?
To fix CVE-2020-6796, users should update Firefox to version 73 or later, or Firefox ESR to version 68.5 or later.
Where can I find more information about CVE-2020-6796?
More information about CVE-2020-6796 can be found on the Mozilla Bugzilla, Mozilla Security Advisories, and Gentoo Security websites.