Bug 1908029 (CVE-2020-35113)
Summary: | CVE-2020-35113 Mozilla: Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | cschalle, erack, gecko-bugs-nobody, jhorak, stransky, tpopela |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | firefox 78.6, thunderbird 78.6 | Doc Type: | If docs needed, set a value |
Doc Text: |
The Mozilla Foundation Security Advisory describes this flaw as:
Mozilla developer reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2020-12-16 10:19:02 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1906545, 1906546, 1906547, 1906548, 1906549, 1906550, 1906553, 1906554, 1906555, 1906556, 1906557, 1906558 | ||
Bug Blocks: | 1906543 |
Description
Guilherme de Almeida Suckevicz
2020-12-15 17:47:14 UTC
Acknowledgments: Name: the Mozilla project Upstream: Christian Holler This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2020:5564 https://access.redhat.com/errata/RHSA-2020:5564 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:5562 https://access.redhat.com/errata/RHSA-2020:5562 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2020:5563 https://access.redhat.com/errata/RHSA-2020:5563 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:5565 https://access.redhat.com/errata/RHSA-2020:5565 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:5561 https://access.redhat.com/errata/RHSA-2020:5561 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-35113 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:5618 https://access.redhat.com/errata/RHSA-2020:5618 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2020:5622 https://access.redhat.com/errata/RHSA-2020:5622 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:5624 https://access.redhat.com/errata/RHSA-2020:5624 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2020:5644 https://access.redhat.com/errata/RHSA-2020:5644 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:5645 https://access.redhat.com/errata/RHSA-2020:5645 |