CVE-2020-6800
Summary
| CVE | CVE-2020-6800 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-02 05:15:00 UTC |
| Updated | 2022-01-01 19:35:00 UTC |
| Description | Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Mozilla Thunderbird: Multiple vulnerabilities (GLSA 202003-10) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| USN-4328-1: Thunderbird vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| USN-4278-2: Firefox vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| Mozilla Firefox: Multiple vulnerabilities (GLSA 202003-02) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Security Vulnerabilities fixed in Firefox 73 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| USN-4335-1: Thunderbird vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| Bug List |
MISC |
bugzilla.mozilla.org |
Broken Link |
| Security Vulnerabilities fixed in Thunderbird 68.5 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Security Vulnerabilities fixed in Firefox ESR68.5 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296076 Oracle Solaris 11.4 Support Repository Update (SRU) 19.3.0 Missing (CPUJAN2020)
- 377025 Alibaba Cloud Linux Security Update for firefox (ALINUX2-SA-2020:0021)
- 377039 Alibaba Cloud Linux Security Update for thunderbird (ALINUX2-SA-2020:0025)
- 500926 Alpine Linux Security Update for firefox-esr
- 502371 Alpine Linux Security Update for thunderbird