Race condition in Mozilla Firefox - CVE-2020-15668
Published: August 25, 2020
Vulnerability identifier: #VU46023
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15668
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a race condition when reading certification information during certificate import. A remote attacker can exploit the race and gain gain access to potentially sensitive data.
Affected software
Mozilla Firefox
Ubuntu
Firefox for Android
firefox (Alpine package)
firefox (Ubuntu package)
Ubuntu
Firefox for Android
firefox (Alpine package)
firefox (Ubuntu package)
How to mitigate CVE-2020-15668
Install updates from vendor's website.
Mozilla Firefox - update to 80.0
Firefox for Android - update to 80.1.2
firefox (Ubuntu package) - addressed in versions 80.0+build2-0ubuntu0.16.04.1, 80.0+build2-0ubuntu0.18.04.1, 80.0+build2-0ubuntu0.20.04.1, 80.0.1+build1-0ubuntu0.16.04.1, 80.0.1+build1-0ubuntu0.18.04.1, 80.0.1+build1-0ubuntu0.20.04.1
Firefox for Android - update to 80.1.2
firefox (Ubuntu package) - addressed in versions 80.0+build2-0ubuntu0.16.04.1, 80.0+build2-0ubuntu0.18.04.1, 80.0+build2-0ubuntu0.20.04.1, 80.0.1+build1-0ubuntu0.16.04.1, 80.0.1+build1-0ubuntu0.18.04.1, 80.0.1+build1-0ubuntu0.20.04.1