Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-12421

Опубликовано: 09 июл. 2020
Источник: debian
EPSS Низкий

Описание

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed78.0-1package
firefox-esrfixed68.10.0esr-1package
thunderbirdfixed1:68.10.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-24/#CVE-2020-12421

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-25/#CVE-2020-12421

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-26/#CVE-2020-12421

EPSS

Процентиль: 81%
0.01493
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

CVSS3: 6.1
redhat
больше 5 лет назад

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

CVSS3: 6.5
nvd
больше 5 лет назад

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

CVSS3: 6.5
github
больше 3 лет назад

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость браузеров Mozilla Firefox, Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю отключить установленные надстройки

EPSS

Процентиль: 81%
0.01493
Низкий