Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5
Published Mar 2, 2020
8.8
HIGHCVSS 3.1
EPSS 2.36%
Description
Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<73
- Version unspecifiedStatusaffectedConstraints<ESR68.5
- Version
-
- Version unspecifiedStatusaffectedConstraints<68.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| |||||||||
| Mozilla | Thunderbird | n/a |
|
Configuration 1
- < 73.0
- < 68.5.0
- < 68.5.0
Configuration 2
- 16.04
- 18.04
- 19.10
No data.
Red Hat Enterprise Linux 6
firefox-0:68.5.0-2.el6_10
Fixed · RHSA-2020:0521
Red Hat Enterprise Linux 6
thunderbird-0:68.5.0-1.el6_10
Fixed · RHSA-2020:0574
Red Hat Enterprise Linux 7
firefox-0:68.5.0-2.el7_7
Fixed · RHSA-2020:0520
Red Hat Enterprise Linux 7
thunderbird-0:68.5.0-1.el7_7
Fixed · RHSA-2020:0576
Red Hat Enterprise Linux 8
firefox-0:68.5.0-2.el8_1
Fixed · RHSA-2020:0512
Red Hat Enterprise Linux 8
thunderbird-0:68.5.0-1.el8_1
Fixed · RHSA-2020:0577
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
firefox-0:68.5.0-2.el8_0
Fixed · RHSA-2020:0519
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
thunderbird-0:68.5.0-1.el8_0
Fixed · RHSA-2020:0565
Red Hat Enterprise Linux 5
firefox
Out of support scope
Red Hat Enterprise Linux 5
thunderbird
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox-0:68.5.0-2.el6_10 | Fixed | RHSA-2020:0521 |
| Red Hat Enterprise Linux 6 | thunderbird-0:68.5.0-1.el6_10 | Fixed | RHSA-2020:0574 |
| Red Hat Enterprise Linux 7 | firefox-0:68.5.0-2.el7_7 | Fixed | RHSA-2020:0520 |
| Red Hat Enterprise Linux 7 | thunderbird-0:68.5.0-1.el7_7 | Fixed | RHSA-2020:0576 |
| Red Hat Enterprise Linux 8 | firefox-0:68.5.0-2.el8_1 | Fixed | RHSA-2020:0512 |
| Red Hat Enterprise Linux 8 | thunderbird-0:68.5.0-1.el8_1 | Fixed | RHSA-2020:0577 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | firefox-0:68.5.0-2.el8_0 | Fixed | RHSA-2020:0519 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | thunderbird-0:68.5.0-1.el8_0 | Fixed | RHSA-2020:0565 |
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | thunderbird | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- https://access.redhat.com/security/cve/CVE-2020-6800 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1595786%2C1596706%2C1598543%2C1604851%2C1608580%2C1608785%2C1605777 x_refsource_MISCBroken LinkIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1801920 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27947 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-6800
- https://security.gentoo.org/glsa/202003-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.gentoo.org/glsa/202003-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4278-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4328-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4335-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-6800
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-06/#CVE-2020-6800
- https://www.mozilla.org/security/advisories/mfsa2020-05/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-06/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-07/ x_refsource_MISCVendor Advisory
Change history (0)
No recorded changes yet.