Input validation error in Firefox ESR and Mozilla Firefox - CVE-2020-12393

 

Input validation error in Firefox ESR and Mozilla Firefox - CVE-2020-12393

Published: May 5, 2020


Vulnerability identifier: #VU27536
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12393
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to the "Copy as cURL" feature of Devtools network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution.

Note, this vulnerability affects Windows installations only.


Affected software

Firefox ESR
Mozilla Firefox
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)
thunderbird (Alpine package)

How to mitigate CVE-2020-12393

Install updates from vendor's website.

Firefox ESR - update to 68.8.0
Mozilla Firefox - update to 76.0
Mozilla Thunderbird - update to 68.8.0
firefox (Alpine package) - update to 76.0-r0
firefox-esr (Alpine package) - update to 68.8.0-r0
mozjs68 (Alpine package) - update to 68.8.0-r0
thunderbird (Alpine package) - update to 68.8.0-r0

External References

Related Security Bulletins