Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15669

Опубликовано: 25 авг. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 5thunderbirdOut of support scope
Red Hat Enterprise Linux 6firefoxFixedRHSA-2020:355826.08.2020
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2020:364308.09.2020
Red Hat Enterprise Linux 7firefoxFixedRHSA-2020:355626.08.2020
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2020:363107.09.2020
Red Hat Enterprise Linux 8firefoxFixedRHSA-2020:355726.08.2020
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2020:363407.09.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsfirefoxFixedRHSA-2020:355526.08.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsthunderbirdFixedRHSA-2020:363307.09.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1872532Mozilla: Use-After-Free when aborting an operation

EPSS

Процентиль: 63%
0.00451
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 5 лет назад

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
nvd
почти 5 лет назад

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
debian
почти 5 лет назад

When aborting an operation, such as a fetch, an abort signal may be de ...

github
больше 3 лет назад

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
fstec
около 5 лет назад

Уязвимость браузера Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после ее освобождения, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 63%
0.00451
Низкий

8.8 High

CVSS3