Bug 1829346 (CVE-2020-6815)

Summary: CVE-2020-6815 Mozilla: Memory and script safety bugs fixed in Firefox 74
Product: [Other] Security Response Reporter: msiddiqu
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: jhorak, security-response-team, stransky
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: firefox 74 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-04-29 16:32:12 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1829324    

Description msiddiqu 2020-04-29 12:18:40 UTC
Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with enough effort some of these could have been exploited to run arbitrary code.

External Reference:

https://www.mozilla.org/en-US/security/advisories/mfsa2020-08/#CVE-2020-6815

Comment 1 msiddiqu 2020-04-29 12:18:44 UTC
Acknowledgments:

Name: the Mozilla project
Upstream: Jason Kratzer, Boris Zbarsky, Tyson Smith, and Alexandru Michis

Comment 2 Product Security DevOps Team 2020-04-29 16:32:12 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-6815