SB20200310119 - Use-after-free in firefox (Alpine package)
Published: March 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2020-6805)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when removing data about origins in Quota manager in Mozilla Firefox. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=559ca01ce273111fa46352af60e88d74c657c7f5
- https://git.alpinelinux.org/aports/commit/?id=1d258f723c31c630b8159e94a980ef430a9ea27b
- https://git.alpinelinux.org/aports/commit/?id=82e6adffb8c262ce3e9453fbbe8e7fd2406bc48f
- https://git.alpinelinux.org/aports/commit/?id=a16f83f7141a8f92c825dbe6822ff641ad8fa846
- https://git.alpinelinux.org/aports/commit/?id=672f75ca5f5562f95ab35778287af25da1b99013