Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbirdUpgrade firefox-esrUpgrade firefoxUpgrade librewolf | Aug 22, 2024 | Oct 1, 2020 |
| Mfsa2020 36 | — | Upgrade to Mozilla Firefox version 80.0 | Aug 26, 2020 | Aug 25, 2020 |
| Mfsa2020 38 | — | Upgrade to Mozilla Firefox ESR version 78.2 | Aug 26, 2020 | Aug 25, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.2 | Aug 27, 2020 | Aug 25, 2020 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.12.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade SUNWthunderbird-calendar to version 0.5.11-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/browser/firefox to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/plugin-lightning to version 0.5.11-11.4.27.0.1.82.0 on Solaris 11.4 | Jan 19, 2021 | Oct 1, 2020 |
| Suse | — | Upgrade mozillafirefoxUpgrade mozillafirefox-buildsymbolsUpgrade mozillafirefox-branding-upstreamUpgrade mozillafirefox-translations-commonUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-devel | Sep 8, 2020 | Aug 26, 2020 |
| Ubuntu | — | Upgrade firefox | Aug 27, 2020 | Aug 26, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub