CVE-2020-6820

CVSS v3.1 8.1 (High)
81% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.89 % (83th)
0.89% Progress
Affected Products 3
Advisories 32

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-04-24 16:15:13
(4 years ago)
Updated Date
2022-07-12 17:42:04
(2 years ago)
Mozilla Firefox And Thunderbird Use-After-Free Vulnerability (CISA - Known Exploited Vulnerabilities Catalog)
Description
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
Required Action
Apply updates per vendor instructions.
Known to be Used in Ransomware Campaigns
Unknown
Notes
https://nvd.nist.gov/vuln/detail/CVE-2020-6820
Vendor
Mozilla
Product
Firefox and Thunderbird
In CISA Catalog from
2021-11-03
(2 years ago)
Due Date
2022-05-03
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 74.0.1 version cpe:2.3:a:mozilla:firefox < 74.0.1
  Mozilla Firefox Esr prior 68.6.1 version cpe:2.3:a:mozilla:firefox_esr < 68.6.1
  Mozilla Thunderbird prior 68.7.0 version cpe:2.3:a:mozilla:thunderbird < 68.7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...