Beveiligingsadvies

CVE-2020-15669

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-10-01 18:42:09
Laatst bijgewerkt 2024-08-04 13:22:30
Toegewezen door mozilla
CVSS-score geen score
Status PUBLISHED

Beschrijving

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.