Memory leak in Mozilla Firefox - CVE-2020-12407
Published: June 2, 2020 / Updated: July 15, 2020
Vulnerability identifier: #VU28525
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12407
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to view memory contents
The vulnerability exists due memory leak in WebRender. An attacker with physical access to the system can open a specially crafted web page and view contents of GPU memory on screen.
Affected software
Mozilla Firefox
Arch Linux
Gentoo Linux
firefox (Alpine package)
Arch Linux
Gentoo Linux
firefox (Alpine package)
How to mitigate CVE-2020-12407
Install updates from vendor's website.
Mozilla Firefox - update to 77.0
firefox (Alpine package) - update to 77.0-r0
firefox (Alpine package) - update to 77.0-r0