By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade librewolfUpgrade firefox-esrUpgrade thunderbirdUpgrade firefox | Aug 22, 2024 | Oct 1, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Oct 2, 2020 | Oct 2, 2020 |
| Centos_linux | — | Upgrade thunderbirdUpgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade firefox-debugsource | Aug 27, 2020 | Aug 26, 2020 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Aug 28, 2020 | Aug 28, 2020 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade mail-client/thunderbird-bin. | Aug 27, 2020 | Aug 27, 2020 |
| Mfsa2020 36 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 80.0 | Aug 26, 2020 | Aug 25, 2020 |
| Mfsa2020 37 | — | Upgrade to Mozilla Firefox ESR version 68.12Upgrade to the latest version of Mozilla Firefox | Aug 26, 2020 | Aug 25, 2020 |
| Mfsa2020 38 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 78.2 | Aug 26, 2020 | Aug 25, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.2Upgrade to the latest version of Mozilla Thunderbird | Aug 27, 2020 | Aug 25, 2020 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4Upgrade mail/thunderbird to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4Upgrade mail/thunderbird/plugin/plugin-lightning to version 0.5.11-11.4.27.0.1.82.0 on Solaris 11.4Upgrade SUNWthunderbird-calendar to version 0.5.11-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.12.0-11.4.26.0.1.75.2 on Solaris 11.4 | Jan 19, 2021 | Oct 1, 2020 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Aug 28, 2020 | Aug 25, 2020 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade thunderbird-debuginfoNo solution existsUpgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade firefox | Aug 27, 2020 | Aug 26, 2020 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbirdUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefoxUpgrade mozillafirefox-buildsymbols | Sep 5, 2020 | Aug 26, 2020 |
| Ubuntu | — | Upgrade firefox | Aug 27, 2020 | Aug 26, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub