Resource management error in Mozilla Firefox - CVE-2020-26967

 

Resource management error in Mozilla Firefox - CVE-2020-26967

Published: November 17, 2020


Vulnerability identifier: #VU48471
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26967
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to introduce an unexpected behavior.

The vulnerability exists due to improper management of internal resources within Mutation Observers. When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This would lead to internal errors and unexpected behavior in the Screenshots code.


Affected software

Mozilla Firefox
Arch Linux
Ubuntu
firefox (Alpine package)
firefox (Ubuntu package)
Firefox for Android

How to mitigate CVE-2020-26967

Install updates from vendor's website.

Mozilla Firefox - update to 83.0
Firefox for Android - update to 83.0.0
firefox (Ubuntu package) - addressed in versions 83.0+build2-0ubuntu0.16.04.3, 83.0+build2-0ubuntu0.18.04.2, 83.0+build2-0ubuntu0.20.04.1, 83.0+build2-0ubuntu0.20.10.1

External References

Related Security Bulletins