Input validation error in Firefox ESR and Mozilla Firefox - CVE-2020-12393
Published: May 5, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the "Copy as cURL" feature of Devtools network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution.
Note, this vulnerability affects Windows installations only.
Affected software
Mozilla Firefox
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)
thunderbird (Alpine package)
How to mitigate CVE-2020-12393
Mozilla Firefox - update to 76.0
Mozilla Thunderbird - update to 68.8.0
firefox (Alpine package) - update to 76.0-r0
firefox-esr (Alpine package) - update to 68.8.0-r0
mozjs68 (Alpine package) - update to 68.8.0-r0
thunderbird (Alpine package) - update to 68.8.0-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Slackware Linux update for mozilla-firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- Input validation error in thunderbird (Alpine package)
- Input validation error in mozjs68 (Alpine package)
- Input validation error in firefox-esr (Alpine package)
- Input validation error in firefox (Alpine package)