CVE-2020-6799: High severity Mozilla Firefox ESR vulnerability
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party application that insufficiently sanitized URL data. In that situation, clicking a link in the third party application could have been used to retrieve and execute files whose location was supplied through command line arguments. Note: This issue only affects Windows operating systems and when Firefox is configured as the default handler for non-default filetypes. Other operating systems are unaffected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 68.5 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 73 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 73 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 68.5 - Configuration
On Windows, when using Firefox as the default handler for non-default file types, stop using Firefox as the default handler for those file types (the issue only affects Windows when Firefox is the default handler for non-default file types).
Mozilla Firefox on Windows Default handler for non-default file types = not default - Compensating control
Ensure that links/files are opened in an application that properly sanitizes URL data before invoking Firefox (the issue requires a third party application that insufficiently sanitizes URL data when opening a downloaded file via a link).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-6799?
The severity of CVE-2020-6799 is high, with a severity value of 8.8.
How does CVE-2020-6799 affect Mozilla Firefox?
CVE-2020-6799 affects Mozilla Firefox versions up to 68.5 (Firefox ESR) and up to 73.0 (Mozilla Firefox).
How can I fix CVE-2020-6799 in Mozilla Firefox?
To fix CVE-2020-6799 in Mozilla Firefox, update to version 68.5 or higher for Firefox ESR, or version 73 or higher for Mozilla Firefox.
Are Windows systems vulnerable to CVE-2020-6799?
No, Microsoft Windows systems are not vulnerable to CVE-2020-6799.
Where can I find more information about CVE-2020-6799?
You can find more information about CVE-2020-6799 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1606596), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-06/), and [Gentoo Security](https://security.gentoo.org/glsa/202003-02).