SB20200310115 - Out-of-bounds read in firefox (Alpine package)
Published: March 10, 2020 Updated: July 1, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2019-20503)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in sctp_load_addresses_from_init in usrsctp. A remote attacker can pass specially crafted data to the application, trigger out-of-bounds read error and read contents of memory on the system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=739fadc78ad34b35354f0dc51861f882dd8c15e1
- https://git.alpinelinux.org/aports/commit/?id=559ca01ce273111fa46352af60e88d74c657c7f5
- https://git.alpinelinux.org/aports/commit/?id=1d258f723c31c630b8159e94a980ef430a9ea27b
- https://git.alpinelinux.org/aports/commit/?id=82e6adffb8c262ce3e9453fbbe8e7fd2406bc48f
- https://git.alpinelinux.org/aports/commit/?id=a16f83f7141a8f92c825dbe6822ff641ad8fa846
- https://git.alpinelinux.org/aports/commit/?id=672f75ca5f5562f95ab35778287af25da1b99013