CVE-2020-15683
Published: 22 October 2020
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird < 78.4.
Priority
CVSS 3 base score: 9.8
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
Upstream |
Released
(82)
|
Ubuntu 21.04 (Hirsute Hippo) |
Released
(82.0.2+build1-0ubuntu1)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Released
(82.0+build2-0ubuntu0.20.10.1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Released
(82.0+build2-0ubuntu0.20.04.1)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(82.0+build2-0ubuntu0.18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(82.0+build2-0ubuntu0.16.04.5)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
mozjs38 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Does not exist
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Needs triage
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
mozjs52 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Needs triage
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Needs triage
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Needs triage
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Needs triage
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
mozjs60 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Does not exist
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
mozjs68 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Does not exist
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Needs triage
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Needs triage
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
thunderbird Launchpad, Ubuntu, Debian |
Upstream |
Released
(78.4)
|
Ubuntu 21.04 (Hirsute Hippo) |
Released
(1:78.4.3+build1-0ubuntu1)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Released
(1:78.5.0+build3-0ubuntu0.20.10.1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Needs triage
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Needs triage
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Needs triage
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
Notes
Author | Note |
---|---|
tyhicks | mozjs contains a copy of the SpiderMonkey JavaScript engine |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15683
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/#CVE-2020-15683
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-47/#CVE-2020-15683
- https://usn.ubuntu.com/usn/usn-4599-1
- https://usn.ubuntu.com/usn/usn-4599-2
- https://usn.ubuntu.com/usn/usn-4647-1
- NVD
- Launchpad
- Debian