On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
https://bugzilla.mozilla.org/show_bug.cgi?id=1544181
https://usn.ubuntu.com/4335-1/
https://www.mozilla.org/security/advisories/mfsa2020-12/
Source: MITRE
Published: 2020-04-24
Updated: 2020-05-01
Type: CWE-787
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.8
Severity: HIGH
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
147407 | NewStart CGSL MAIN 4.06 : firefox Multiple Vulnerabilities (NS-SA-2021-0004) | Nessus | NewStart CGSL Local Security Checks | critical |
147312 | NewStart CGSL MAIN 4.06 : thunderbird Multiple Vulnerabilities (NS-SA-2021-0002) | Nessus | NewStart CGSL Local Security Checks | critical |
145974 | CentOS 8 : firefox (CESA-2020:1406) | Nessus | CentOS Local Security Checks | high |
145858 | CentOS 8 : thunderbird (CESA-2020:1495) | Nessus | CentOS Local Security Checks | high |
143979 | NewStart CGSL CORE 5.05 / MAIN 5.05 : thunderbird Multiple Vulnerabilities (NS-SA-2020-0093) | Nessus | NewStart CGSL Local Security Checks | critical |
143948 | NewStart CGSL CORE 5.05 / MAIN 5.05 : firefox Multiple Vulnerabilities (NS-SA-2020-0097) | Nessus | NewStart CGSL Local Security Checks | critical |
143928 | NewStart CGSL CORE 5.04 / MAIN 5.04 : firefox Multiple Vulnerabilities (NS-SA-2020-0064) | Nessus | NewStart CGSL Local Security Checks | critical |
143912 | NewStart CGSL CORE 5.04 / MAIN 5.04 : thunderbird Multiple Vulnerabilities (NS-SA-2020-0074) | Nessus | NewStart CGSL Local Security Checks | critical |
138776 | NewStart CGSL MAIN 6.01 : thunderbird Multiple Vulnerabilities (NS-SA-2020-0036) | Nessus | NewStart CGSL Local Security Checks | critical |
137246 | RHEL 8 : firefox (RHSA-2020:1406) | Nessus | Red Hat Local Security Checks | high |
137245 | RHEL 8 : firefox (RHSA-2020:1404) | Nessus | Red Hat Local Security Checks | high |
136752 | Amazon Linux 2 : thunderbird (ALAS-2020-1429) | Nessus | Amazon Linux Local Security Checks | critical |
136194 | CentOS 7 : thunderbird (CESA-2020:1489) | Nessus | CentOS Local Security Checks | high |
136017 | CentOS 6 : thunderbird (CESA-2020:1488) | Nessus | CentOS Local Security Checks | high |
136016 | CentOS 6 : firefox (CESA-2020:1429) | Nessus | CentOS Local Security Checks | high |
136007 | openSUSE Security Update : MozillaThunderbird (openSUSE-2020-544) | Nessus | SuSE Local Security Checks | high |
135947 | GLSA-202004-11 : Mozilla Firefox: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
135896 | Ubuntu 16.04 LTS : Thunderbird vulnerabilities (USN-4335-1) | Nessus | Ubuntu Local Security Checks | high |
135845 | Scientific Linux Security Update : thunderbird on SL7.x x86_64 (20200416) | Nessus | Scientific Linux Local Security Checks | high |
135844 | Scientific Linux Security Update : firefox on SL7.x x86_64 (20200409) | Nessus | Scientific Linux Local Security Checks | high |
135747 | Oracle Linux 8 : thunderbird (ELSA-2020-1495) | Nessus | Oracle Linux Local Security Checks | high |
135716 | Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20200416) | Nessus | Scientific Linux Local Security Checks | high |
135715 | Oracle Linux 7 : thunderbird (ELSA-2020-1489) | Nessus | Oracle Linux Local Security Checks | high |
135692 | RHEL 8 : thunderbird (RHSA-2020:1495) | Nessus | Red Hat Local Security Checks | high |
135691 | RHEL 8 : thunderbird (RHSA-2020:1496) | Nessus | Red Hat Local Security Checks | high |
135687 | RHEL 6 : thunderbird (RHSA-2020:1488) | Nessus | Red Hat Local Security Checks | high |
135684 | RHEL 7 : thunderbird (RHSA-2020:1489) | Nessus | Red Hat Local Security Checks | high |
135578 | openSUSE Security Update : MozillaThunderbird (openSUSE-2020-520) | Nessus | SuSE Local Security Checks | high |
135575 | Scientific Linux Security Update : firefox on SL6.x i386/x86_64 (20200414) | Nessus | Scientific Linux Local Security Checks | high |
135495 | Debian DLA-2172-1 : thunderbird security update | Nessus | Debian Local Security Checks | high |
135455 | Ubuntu 18.04 LTS / 19.10 : Thunderbird vulnerabilities (USN-4328-1) | Nessus | Ubuntu Local Security Checks | high |
135446 | openSUSE Security Update : MozillaFirefox (openSUSE-2020-493) | Nessus | SuSE Local Security Checks | high |
135431 | Oracle Linux 7 : firefox (ELSA-2020-1420) | Nessus | Oracle Linux Local Security Checks | high |
135417 | Debian DSA-4656-1 : thunderbird - security update | Nessus | Debian Local Security Checks | high |
135415 | RHEL 6 : firefox (RHSA-2020:1429) | Nessus | Red Hat Local Security Checks | high |
135413 | Mozilla Thunderbird < 68.7.0 | Nessus | Windows | high |
135412 | Mozilla Thunderbird < 68.7.0 | Nessus | MacOS X Local Security Checks | high |
135397 | SUSE SLES12 Security Update : MozillaFirefox (SUSE-SU-2020:0978-1) | Nessus | SuSE Local Security Checks | high |
135396 | SUSE SLED15 / SLES15 Security Update : MozillaFirefox (SUSE-SU-2020:0971-1) | Nessus | SuSE Local Security Checks | high |
135380 | Oracle Linux 8 : firefox (ELSA-2020-1406) | Nessus | Oracle Linux Local Security Checks | high |
135366 | Debian DSA-4655-1 : firefox-esr - security update | Nessus | Debian Local Security Checks | high |
135363 | Debian DLA-2170-1 : firefox-esr security update | Nessus | Debian Local Security Checks | high |
135288 | RHEL 7 : firefox (RHSA-2020:1420) | Nessus | Red Hat Local Security Checks | high |
135284 | Ubuntu 16.04 LTS / 18.04 LTS / 19.10 : firefox vulnerabilities (USN-4323-1) | Nessus | Ubuntu Local Security Checks | high |
135280 | Slackware 14.2 / current : mozilla-firefox (SSA:2020-098-01) | Nessus | Slackware Local Security Checks | high |
135276 | Mozilla Firefox < 75.0 (mfsa2020-12) | Nessus | Windows | high |
135275 | Mozilla Firefox < 75.0 Multiple Vulnerabilities (mfsa2020-12) | Nessus | MacOS X Local Security Checks | high |
135274 | Mozilla Firefox ESR < 68.7 Multiple Vulnerabilities (mfsa2020-13) | Nessus | Windows | high |
135273 | Mozilla Firefox ESR < 68.7 Multiple Vulnerabilities (mfsa2020-13) | Nessus | MacOS X Local Security Checks | high |