CVE-2020-15659
Summary
| CVE | CVE-2020-15659 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-10 18:15:00 UTC |
| Updated | 2020-08-21 18:21:00 UTC |
| Description | Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Vulnerabilities fixed in Firefox 79 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Security Vulnerabilities fixed in Firefox ESR 68.11 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| [security-announce] openSUSE-SU-2020:1189-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:1205-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Patch, Third Party Advisory |
| Security Vulnerabilities fixed in Firefox ESR 78.1 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Security Vulnerabilities fixed in Thunderbird 78.1 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| USN-4443-1: Firefox vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Patch, Third Party Advisory |
| Bug List |
MISC |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Vendor Advisory |
| [security-announce] openSUSE-SU-2020:1179-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Patch, Third Party Advisory |
| Security Vulnerabilities fixed in Thunderbird 68.11 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296072 Oracle Solaris 11.4 Support Repository Update (SRU) 25.75.3 Missing (CPUJUL2020)
- 377050 Alibaba Cloud Linux Security Update for firefox (ALINUX2-SA-2020:0109)
- 500932 Alpine Linux Security Update for firefox-esr
- 500952 Alpine Linux Security Update for firefox
- 501075 Alpine Linux Security Update for mozjs68
- 503837 Alpine Linux Security Update for firefox