Race condition in Mozilla Firefox - CVE-2020-15668

 

Race condition in Mozilla Firefox - CVE-2020-15668

Published: August 25, 2020


Vulnerability identifier: #VU46023
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15668
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a race condition when reading certification information during certificate import. A remote attacker can exploit the race and gain gain access to potentially sensitive data.


Affected software

Mozilla Firefox
Ubuntu
Firefox for Android
firefox (Alpine package)
firefox (Ubuntu package)

How to mitigate CVE-2020-15668

Install updates from vendor's website.

Mozilla Firefox - update to 80.0
Firefox for Android - update to 80.1.2
firefox (Ubuntu package) - addressed in versions 80.0+build2-0ubuntu0.16.04.1, 80.0+build2-0ubuntu0.18.04.1, 80.0+build2-0ubuntu0.20.04.1, 80.0.1+build1-0ubuntu0.16.04.1, 80.0.1+build1-0ubuntu0.18.04.1, 80.0.1+build1-0ubuntu0.20.04.1

External References

Related Security Bulletins