ID | CVE-2020-15678 |
Summary | When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3. |
References | |
Vulnerable Configurations | |
CVSS | Base: | 5.0 | Impact: | | Exploitability: | |
|
Access | Vector | Complexity | Authentication | | | |
|
Impact | Confidentiality | Integrity | Availability | | | |
|
redhat via4 | advisories | bugzilla | id | 1881667 | title | CVE-2020-15673 Mozilla: Memory safety bugs fixed in Firefox 81 and Firefox ESR 78.3 |
| oval | OR | comment | Red Hat Enterprise Linux must be installed | oval | oval:com.redhat.rhba:tst:20070304026 |
AND | comment | Red Hat Enterprise Linux 8 is installed | oval | oval:com.redhat.rhba:tst:20193384074 |
OR | AND | comment | firefox is earlier than 0:78.3.0-1.el8_2 | oval | oval:com.redhat.rhsa:tst:20203832001 |
comment | firefox is signed with Red Hat redhatrelease2 key | oval | oval:com.redhat.rhsa:tst:20100861006 |
|
AND | comment | firefox-debugsource is earlier than 0:78.3.0-1.el8_2 | oval | oval:com.redhat.rhsa:tst:20203832003 |
comment | firefox-debugsource is signed with Red Hat redhatrelease2 key | oval | oval:com.redhat.rhsa:tst:20190966004 |
|
|
|
|
| rhsa | id | RHSA-2020:3832 | released | 2020-09-24 | severity | Important | title | RHSA-2020:3832: firefox security update (Important) |
|
bugzilla | id | 1881667 | title | CVE-2020-15673 Mozilla: Memory safety bugs fixed in Firefox 81 and Firefox ESR 78.3 |
| oval | OR | comment | Red Hat Enterprise Linux must be installed | oval | oval:com.redhat.rhba:tst:20070304026 |
AND | comment | Red Hat Enterprise Linux 6 is installed | oval | oval:com.redhat.rhba:tst:20111656003 |
comment | firefox is earlier than 0:78.3.0-1.el6_10 | oval | oval:com.redhat.rhsa:tst:20203835001 |
comment | firefox is signed with Red Hat redhatrelease2 key | oval | oval:com.redhat.rhsa:tst:20100861006 |
|
|
| rhsa | id | RHSA-2020:3835 | released | 2020-09-24 | severity | Important | title | RHSA-2020:3835: firefox security update (Important) |
|
| rpms | - firefox-0:78.3.0-1.el8_2
- firefox-debuginfo-0:78.3.0-1.el8_2
- firefox-debugsource-0:78.3.0-1.el8_2
- firefox-0:78.3.0-1.el8_1
- firefox-debuginfo-0:78.3.0-1.el8_1
- firefox-debugsource-0:78.3.0-1.el8_1
- firefox-0:78.3.0-1.el8_0
- firefox-debuginfo-0:78.3.0-1.el8_0
- firefox-debugsource-0:78.3.0-1.el8_0
- firefox-0:78.3.0-1.el6_10
- firefox-debuginfo-0:78.3.0-1.el6_10
|
|
Last major update | 01-10-2020 – 19:20 |
Published | 01-10-2020 – 19:15 |
Last modified | 01-10-2020 – 19:20 |