Back

HIGH

Mozilla: BodyStream:: OnInputStreamReady was missing protections against state confusion

Published Mar 25, 2020

Description

By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

Affected products

Remediation

No remediation recorded yet.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Mar 25, 2020
Updated Aug 4, 2024
Reserved Jan 10, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 10, 2020