Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mozjs68Upgrade firefoxUpgrade firefox-esrUpgrade thunderbirdUpgrade librewolf | Aug 22, 2024 | Apr 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | May 22, 2020 | Apr 24, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 24, 2020 |
| Centos_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird-debuginfo | Apr 8, 2020 | Apr 7, 2020 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Apr 6, 2020 | Apr 6, 2020 |
| Gentoo Linux | — | Upgrade www-client/firefox. | Apr 6, 2020 | Apr 4, 2020 |
| Mfsa2020 11 | — | Upgrade to Mozilla Firefox ESR version 68.6.1Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 74.0.1 | Apr 6, 2020 | Apr 3, 2020 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 68.7 | Apr 13, 2020 | Apr 9, 2020 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade web/browser/firefox to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade consolidation/userland/userland-incorporation to version 11.4-11.4.24.0.1.75.1 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4 | Jan 19, 2021 | Apr 24, 2020 |
| Oracle_linux | — | Upgrade firefoxUpgrade thunderbird | Apr 11, 2020 | Apr 3, 2020 |
| Redhat_linux | — | Upgrade firefoxUpgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade firefox-debuginfoNo solution existsUpgrade thunderbird-debuginfoUpgrade firefox-debugsource | Apr 8, 2020 | Apr 7, 2020 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbirdUpgrade MozillaFirefoxUpgrade mozillafirefox-branding-upstreamUpgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-buildsymbols | Apr 7, 2020 | Apr 4, 2020 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Apr 5, 2020 | Apr 4, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub