CRITICAL
Mozilla: Memory safety bugs fixed in Firefox 82
Published Oct 22, 2020
9.8
CRITICALCVSS 3.1
EPSS 1.34%
Description
Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.
Affected products
-
Affected
- ≥ unspecified, < 82
No data.
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://access.redhat.com/security/cve/CVE-2020-15684 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1653764%2C1661402%2C1662259%2C1664257 x_refsource_MISCBroken LinkIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1963792 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7671 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-15684
- https://www.cve.org/CVERecord?id=CVE-2020-15684
- https://www.mozilla.org/security/advisories/mfsa2020-45/ x_refsource_MISCRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-15684 | Vendor Advisory | |
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1653764%2C1661402%2C1662259%2C1664257 | x_refsource_MISCBroken LinkIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1963792 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7671 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-15684 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-15684 | ||
| https://www.mozilla.org/security/advisories/mfsa2020-45/ | x_refsource_MISCRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Oct 22, 2020
Updated Aug 4, 2024
Reserved Jul 10, 2020
Link CVE-2020-15684
CISA Vulnrichment
No data
GitHub
No data