When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Oct 2, 2020 | Oct 2, 2020 |
| Centos_linux | — | Upgrade firefoxUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade thunderbirdUpgrade firefox-debugsource | Aug 27, 2020 | Aug 26, 2020 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Aug 28, 2020 | Aug 28, 2020 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox. | Aug 27, 2020 | Aug 27, 2020 |
| Mfsa2020 37 | — | Upgrade to Mozilla Firefox ESR version 68.12Upgrade to the latest version of Mozilla Firefox | Aug 26, 2020 | Aug 25, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.12Upgrade to the latest version of Mozilla Thunderbird | Aug 27, 2020 | Aug 25, 2020 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Aug 28, 2020 | Aug 25, 2020 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefox-debugsourceUpgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade firefoxNo solution exists | Aug 27, 2020 | Aug 26, 2020 |
| Suse | — | Upgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird | Sep 9, 2020 | Aug 27, 2020 |
| Ubuntu | — | Upgrade thunderbird | Nov 19, 2024 | Oct 1, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub