Use-after-free in Mozilla Firefox - CVE-2020-12416

 

Use-after-free in Mozilla Firefox - CVE-2020-12416

Published: July 2, 2020 / Updated: July 31, 2020


Vulnerability identifier: #VU29458
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12416
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in WebRTC VideoBroadcaster. A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Mozilla Firefox
Gentoo Linux
Opensuse
Ubuntu
Mozilla Thunderbird
firefox (Alpine package)
firefox (Ubuntu package)

How to mitigate CVE-2020-12416

Install updates from vendor's website.

Mozilla Firefox - update to 78.0.1
Mozilla Thunderbird - addressed in versions 68.10.0, 78.0
firefox (Alpine package) - update to 78.0.1-r0
firefox (Ubuntu package) - addressed in versions 78.0.1+build1-0ubuntu0.16.04.1, 78.0.1+build1-0ubuntu0.18.04.1, 78.0.1+build1-0ubuntu0.19.10.1, 78.0.1+build1-0ubuntu0.20.04.1

External References

Related Security Bulletins