CVE-2020-6812
Published: 11 March 2020
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Priority
CVSS 3 base score: 5.3
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
bionic |
Released
(74.0+build3-0ubuntu0.18.04.1)
|
eoan |
Released
(74.0+build3-0ubuntu0.19.10.1)
|
|
focal |
Released
(74.0+build3-0ubuntu1)
|
|
groovy |
Released
(74.0+build3-0ubuntu1)
|
|
hirsute |
Released
(74.0+build3-0ubuntu1)
|
|
impish |
Released
(74.0+build3-0ubuntu1)
|
|
jammy |
Released
(74.0+build3-0ubuntu1)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(74.0)
|
|
xenial |
Released
(74.0+build3-0ubuntu0.16.04.1)
|
|
mozjs38 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
mozjs52 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
eoan |
Ignored
(reached end-of-life)
|
|
focal |
Needs triage
|
|
groovy |
Ignored
(reached end-of-life)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
mozjs60 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
eoan |
Ignored
(reached end-of-life)
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
thunderbird Launchpad, Ubuntu, Debian |
bionic |
Released
(1:68.7.0+build1-0ubuntu0.18.04.1)
|
eoan |
Released
(1:68.7.0+build1-0ubuntu0.19.10.1)
|
|
focal |
Released
(1:68.6.0+build2-0ubuntu1)
|
|
groovy |
Released
(1:68.6.0+build2-0ubuntu1)
|
|
hirsute |
Released
(1:68.6.0+build2-0ubuntu1)
|
|
impish |
Released
(1:68.6.0+build2-0ubuntu1)
|
|
jammy |
Released
(1:68.6.0+build2-0ubuntu1)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(68.6.0)
|
|
xenial |
Released
(1:68.7.0+build1-0ubuntu0.16.04.2)
|
Notes
Author | Note |
---|---|
tyhicks | mozjs contains a copy of the SpiderMonkey JavaScript engine |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6812
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-09/#CVE-2020-6812
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-08/#CVE-2020-6812
- https://ubuntu.com/security/notices/USN-4299-1
- https://ubuntu.com/security/notices/USN-4328-1
- https://ubuntu.com/security/notices/USN-4335-1
- NVD
- Launchpad
- Debian