Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-26950

Опубликовано: 09 нояб. 2020
Источник: redhat
CVSS3: 8.8

Описание

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 5thunderbirdOut of support scope
Red Hat Enterprise Linux 6firefoxFixedRHSA-2020:510412.11.2020
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2020:516423.11.2020
Red Hat Enterprise Linux 7firefoxFixedRHSA-2020:509912.11.2020
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2020:516323.11.2020
Red Hat Enterprise Linux 8firefoxFixedRHSA-2020:510012.11.2020
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2020:514618.11.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsfirefoxFixedRHSA-2020:513817.11.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsthunderbirdFixedRHSA-2020:516723.11.2020

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1896306Mozilla: Write side effects in MCallGetProperty opcode not accounted for

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 5 лет назад

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

CVSS3: 8.8
nvd
около 5 лет назад

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

CVSS3: 8.8
debian
около 5 лет назад

In certain circumstances, the MCallGetProperty opcode can be emitted w ...

suse-cvrf
около 5 лет назад

Security update for MozillaThunderbird

suse-cvrf
около 5 лет назад

Security update for MozillaThunderbird

8.8 High

CVSS3