Buffer overflow in Mozilla Firefox - CVE-2020-26952
Published: November 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing HTML content. The incorrect bookkeeping of functions inlined during JIT compilation when handling out-of-memory errors can trigger memory corruption and allow remote code execution.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
Ubuntu
firefox (Alpine package)
firefox (Ubuntu package)
Firefox for Android
How to mitigate CVE-2020-26952
Firefox for Android - update to 83.0.0
firefox (Ubuntu package) - addressed in versions 83.0+build2-0ubuntu0.16.04.3, 83.0+build2-0ubuntu0.18.04.2, 83.0+build2-0ubuntu0.20.04.1, 83.0+build2-0ubuntu0.20.10.1