HIGH
Mozilla: Memory safety bugs fixed in Firefox 73
Published Mar 2, 2020
8.8
HIGHCVSS 3.1
EPSS 1.41%
Description
Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 73.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<73
- Version
Configuration 2
- 16.04
No data.
Red Hat Enterprise Linux 5
firefox
Out of support scope
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://access.redhat.com/security/cve/CVE-2020-6801 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1601024%2C1601712%2C1604836%2C1606492 x_refsource_MISCBroken LinkIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1829100 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2020-6801
- https://usn.ubuntu.com/4278-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-6801
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-05/#CVE-2020-6801
- https://www.mozilla.org/security/advisories/mfsa2020-05/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-6801 | Vendor Advisory | |
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1601024%2C1601712%2C1604836%2C1606492 | x_refsource_MISCBroken LinkIssue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1829100 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-6801 | ||
| https://usn.ubuntu.com/4278-2/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-6801 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2020-05/#CVE-2020-6801 | ||
| https://www.mozilla.org/security/advisories/mfsa2020-05/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Mar 2, 2020
Updated Aug 4, 2024
Reserved Jan 10, 2020
Link CVE-2020-6801
CISA Vulnrichment
Updated n/a