Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2020-39/ | release notes vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2020-41/ | release notes vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2020-36/ | release notes vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2020-38/ | release notes vendor advisory |
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1651001%2C1653626%2C1656957 | issue tracking vendor advisory broken link |