By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade librewolfUpgrade firefox-esr | Aug 22, 2024 | Oct 1, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Oct 2, 2020 | Oct 2, 2020 |
| Centos_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefoxUpgrade firefox-debugsource | Aug 27, 2020 | Aug 26, 2020 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Aug 28, 2020 | Aug 28, 2020 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin. | Aug 27, 2020 | Aug 27, 2020 |
| Mfsa2020 36 | — | Upgrade to Mozilla Firefox version 80.0Upgrade to the latest version of Mozilla Firefox | Aug 26, 2020 | Aug 25, 2020 |
| Mfsa2020 37 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 68.12 | Aug 26, 2020 | Aug 25, 2020 |
| Mfsa2020 38 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 78.2 | Aug 26, 2020 | Aug 25, 2020 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 78.2 | Aug 27, 2020 | Aug 25, 2020 |
| Oracle Solaris | — | Upgrade SUNWthunderbird-calendar to version 0.5.11-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/plugin-lightning to version 0.5.11-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/browser/firefox to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4Upgrade mail/thunderbird to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4 | Jan 19, 2021 | Oct 1, 2020 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Aug 28, 2020 | Aug 25, 2020 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debugsourceNo solution existsUpgrade firefox-debuginfo | Aug 27, 2020 | Aug 26, 2020 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade mozillafirefox-buildsymbolsUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbirdUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-translations-other | Sep 5, 2020 | Aug 26, 2020 |
| Ubuntu | — | Upgrade firefox | Aug 27, 2020 | Aug 26, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub