Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbirdUpgrade librewolfUpgrade firefox-esrUpgrade mozjs68Upgrade firefox | Aug 22, 2024 | Apr 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | May 22, 2020 | Apr 24, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 24, 2020 |
| Centos_linux | — | Upgrade firefoxUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefox-debugsourceUpgrade thunderbirdUpgrade thunderbird-debugsource | Apr 8, 2020 | Apr 7, 2020 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Apr 6, 2020 | Apr 6, 2020 |
| Gentoo Linux | — | Upgrade www-client/firefox. | Apr 6, 2020 | Apr 4, 2020 |
| Mfsa2020 11 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 68.6.1Upgrade to Mozilla Firefox version 74.0.1 | Apr 6, 2020 | Apr 3, 2020 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 68.7 | Apr 13, 2020 | Apr 9, 2020 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade consolidation/userland/userland-incorporation to version 11.4-11.4.24.0.1.75.1 on Solaris 11.4Upgrade web/browser/firefox to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade mail/thunderbird to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4 | Jan 19, 2021 | Apr 24, 2020 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Apr 11, 2020 | Apr 3, 2020 |
| Redhat_linux | — | Upgrade firefox-debuginfoNo solution existsUpgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade thunderbird | Apr 8, 2020 | Apr 7, 2020 |
| Suse | — | Upgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade mozillafirefox-buildsymbolsUpgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-devel | Apr 7, 2020 | Apr 4, 2020 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Apr 5, 2020 | Apr 4, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub