CVE-2020-6812
Summary
| CVE | CVE-2020-6812 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-25 22:15:00 UTC |
| Updated | 2023-02-23 02:23:00 UTC |
| Description | The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Vulnerabilities fixed in Firefox ESR 68.6 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Security Vulnerabilities fixed in Firefox 74 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| USN-4328-1: Thunderbird vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Security Vulnerabilities fixed in Thunderbird 68.6 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| 1616661 - (CVE-2020-6812) AirPods labels with personally identifiable information should not be exposed to the web |
MISC |
bugzilla.mozilla.org |
Permissions Required, Vendor Advisory |
| USN-4335-1: Thunderbird vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178553 Debian Security Update for firefox-esr (DLA 2140-1)
- 377015 Alibaba Cloud Linux Security Update for firefox (ALINUX2-SA-2020:0036)
- 377080 Alibaba Cloud Linux Security Update for thunderbird (ALINUX2-SA-2020:0037)
- 500927 Alpine Linux Security Update for firefox-esr
- 500946 Alpine Linux Security Update for firefox
- 501076 Alpine Linux Security Update for mozjs68
- 502372 Alpine Linux Security Update for thunderbird
- 503831 Alpine Linux Security Update for firefox
- 504792 Alpine Linux Security Update for firefox-esr
- 505440 Alpine Linux Security Update for thunderbird