During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2020 01 | mozilla-firefox-upgrade-72_0 | Jan 8, 2020 | Jan 7, 2020 | |
| Mfsa2020 02 | mozilla-firefox-esr-upgrade-68_4 | Jan 8, 2020 | Jan 7, 2020 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-68_4_1 | Jan 13, 2020 | Jan 8, 2020 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-mail-thunderbird-68-4-1-11-4-18-0-1-3-0oracle-solaris-11-4-upgrade-mail-thunderbird-plugin-thunderbird-lightning-68-4-1-11-4-18-0-1-3-0oracle-solaris-11-4-upgrade-web-browser-firefox-68-4-1-11-4-18-0-1-3-0oracle-solaris-11-4-upgrade-web-data-firefox-bookmarks-68-4-1-11-4-18-0-1-3-0 | Jan 19, 2021 | Jan 8, 2020 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-buildsymbolssuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Jan 11, 2020 | Jan 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub