Improper access control in Firefox ESR and Mozilla Firefox - CVE-2020-6797
Published: February 11, 2020 / Updated: February 12, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions imposed on extensions that are granted downloads.open permission. A remote attacker can bypass implemented security restrictions and launch or open arbitrary application on the system.
Note: the vulnerability affects Mac OSX users only.Affected software
Mozilla Firefox
Gentoo Linux
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)
thunderbird (Alpine package)
How to mitigate CVE-2020-6797
Mozilla Firefox - update to 73.0
Mozilla Thunderbird - update to 68.5.0
firefox-esr (Alpine package) - update to 68.5.0-r0
thunderbird (Alpine package) - update to 68.5.0-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-thunderbird
- Slackware Linux update for mozilla-firefox
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- Gentoo update for Mozilla Firefox
- Improper access control in thunderbird (Alpine package)
- Improper access control in firefox-esr (Alpine package)