CVE-2020-15669

Description

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.451

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-15663,CVE-2020-15664,CVE-2020-15669 are fixed in Mozilla Firefox ESR (68.12.0)Windows
Vulnerabilities CVE-2020-15663,CVE-2020-15664,CVE-2020-15669 are fixed in Mozilla Firefox ESR (x64) (68.12.0)Windows
Multiple vulnerabilities affected in Mozilla Thunderbird (68.12)Windows
Multiple vulnerabilities affected in Mozilla Thunderbird (x64) (68.12)Windows
Vulnerability CVE-2020-15669 are affected in Mozilla Firefox ESR (x64) 68.11.0Windows
Vulnerability CVE-2020-15669 are affected in Mozilla Firefox ESR 68.11.0Windows
Vulnerabilities CVE-2020-15663,CVE-2020-15664,CVE-2020-15669 are fixed in Mozilla Thunderbird For Mac 68.12Mac
Vulnerabilities CVE-2020-15663,CVE-2020-15664,CVE-2020-15669 are affected in Mozilla Thunderbird for Mac 68.11Mac
Vulnerabilities CVE-2020-15664,CVE-2020-15669 are affected in Firefox ESR for Mac 68.11.0Mac
Vulnerabilities CVE-2020-15664,CVE-2020-15669 are affected in Mozilla Firefox for Mac 68.11.0Mac
Vulnerabilities CVE-2020-15669,CVE-2020-15663,CVE-2020-15664 are fixed in Mozilla Firefox For Mac 68.12Mac
firefox-esr security update(DSA-4749-1) firefox-esr_68.12.0esr-1~deb10u1_i386.debLinux
firefox-esr security update(DSA-4749-1) firefox-esr_68.12.0esr-1~deb10u1_amd64.debLinux
thunderbird security update(DSA-4754-1) thunderbird_68.12.0-1~deb10u1_i386.debLinux
thunderbird security update(DSA-4754-1) thunderbird_68.12.0-1~deb10u1_amd64.debLinux
(RHSA-2020:3556) firefox security update firefox-68.12.0-1.el7_8.i686.rpmLinux
(RHSA-2020:3556) firefox security update firefox-68.12.0-1.el7_8.x86_64.rpmLinux
(RHSA-2020:3557) firefox security update firefox-78.2.0-2.el8_2.x86_64.rpmLinux
(RHSA-2020:3557) firefox security update firefox-debugsource-78.2.0-2.el8_2.x86_64.rpmLinux
(RHSA-2020:3558) firefox security update firefox-68.12.0-1.el6_10.i686.rpmLinux
(RHSA-2020:3558) firefox security update firefox-68.12.0-1.el6_10.i686.rpmLinux
(RHSA-2020:3558) firefox security update firefox-68.12.0-1.el6_10.x86_64.rpmLinux
(RHSA-2020:3558) firefox security update firefox-68.12.0-1.el6_10.i686.rpmLinux
(RHSA-2020:3558) firefox security update firefox-68.12.0-1.el6_10.x86_64.rpmLinux
(RHSA-2020:3631) thunderbird security update thunderbird-68.12.0-1.el7_8.x86_64.rpmLinux
(RHSA-2020:3643) thunderbird security update thunderbird-68.12.0-1.el6_10.i686.rpmLinux
(RHSA-2020:3643) thunderbird security update thunderbird-68.12.0-1.el6_10.x86_64.rpmLinux
(CESA-2020:3557) firefox security update firefox-78.2.0-2.el8_2.x86_64.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-315675Mozilla Firefox ESR (68.12.0)
PATCH-315677Mozilla Firefox ESR (x64) (68.12.0)
PATCH-315938Mozilla Thunderbird (68.12.0)
PATCH-315939Mozilla Thunderbird (x64) (68.12.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-612783Mozilla Firefox For Mac (145.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234