A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 73 and Firefox < ESR68.5.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2020-05/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2020-06/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1610426 | permissions required |
https://usn.ubuntu.com/4278-2/ | vendor advisory |
https://security.gentoo.org/glsa/202003-02 | vendor advisory |