CVE-2020-15969: Use after free in WebRTC
A use-after-free bug in the usersctp library was reported upstream. We assume this could have led to memory corruption and a potentially exploitable crash.
Other sources
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
WebRTC. A use after free issue was addressed with improved memory management.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-29610
- CVE-2020-27948
- CVE-2020-29608
- CVE-2020-27946
- CVE-2020-27943
- CVE-2020-27944
- CVE-2020-29624
- CVE-2020-29615
- CVE-2020-29617
- CVE-2020-29619
- CVE-2020-29618
- CVE-2020-29611
- CVE-2020-29614
- CVE-2020-9972
- CVE-2020-29623
- CVE-2020-15969
- CVE-2021-31077
- CVE-2020-27914
- CVE-2020-27915
- CVE-2020-27936
- CVE-2020-27903
- CVE-2020-27941
- CVE-2020-29621
- CVE-2020-27910
- CVE-2020-9943
- CVE-2020-9944
- CVE-2020-27916
- CVE-2020-27906
- CVE-2020-27908
- CVE-2020-9960
- CVE-2020-10017
- CVE-2020-27922
- CVE-2020-10001
- CVE-2020-9962
- CVE-2020-27952
- CVE-2020-9956
- CVE-2020-27931
- CVE-2020-10002
- CVE-2020-27947
- CVE-2020-29612
- CVE-2020-9978
- CVE-2020-27939
- CVE-2020-29625
- CVE-2020-29616
- CVE-2020-27924
- CVE-2020-27912
- CVE-2020-27923
- CVE-2020-27919
- CVE-2020-10015
- CVE-2020-27897
- CVE-2020-27907
- CVE-2020-9974
- CVE-2020-10016
- CVE-2020-9967
- CVE-2020-9975
- CVE-2020-27921
- CVE-2020-27949
- CVE-2020-29620
- CVE-2020-27911
- CVE-2020-27920
- CVE-2020-27926
- CVE-2020-10014
- CVE-2020-10010
- CVE-2020-29633
- CVE-2020-13520
- CVE-2020-13524
- CVE-2020-10004
- CVE-2020-27901
- CVE-2020-27938
- CVE-2020-10007
- CVE-2020-10012
- CVE-2020-27896
- CVE-2020-10009
- CVE-2020-27898
- CVE-2020-27951
- CVE-2020-15683
- CVE-2020-15254
- CVE-2020-15680
- CVE-2020-15681
- CVE-2020-15682
- CVE-2020-15684
- CVE-2020-15967
- CVE-2020-15968
- CVE-2020-15970
- CVE-2020-15971
- CVE-2020-15972
- CVE-2020-15990
- CVE-2020-15991
- CVE-2020-15973
- CVE-2020-15974
- CVE-2020-15975
- CVE-2020-15976
- CVE-2020-6557
- CVE-2020-15977
- CVE-2020-15978
- CVE-2020-15979
- CVE-2020-15980
- CVE-2020-15981
- CVE-2020-15982
- CVE-2020-15983
- CVE-2020-15984
- CVE-2020-15985
- CVE-2020-15986
- CVE-2020-15987
- CVE-2020-15992
- CVE-2020-15988
- CVE-2020-15989
- CVE-2020-29613
Frequently Asked Questions
What is CVE-2020-15969?
CVE-2020-15969 is a use-after-free issue in the WebRTC usersctp library.
What is the severity of CVE-2020-15969?
CVE-2020-15969 has a severity rating of high (7).
Which products are affected by CVE-2020-15969?
CVE-2020-15969 affects Apple macOS Big Sur (up to version 11.1), Apple Catalina, Apple Mojave, Mozilla Firefox (up to version 82), Apple iOS (up to version 14.3), Apple iPadOS (up to version 14.3), Apple Safari (up to version 14.0.2), Apple watchOS (up to version 7.2), Apple tvOS (up to version 14.3), Mozilla Thunderbird (up to version 78.4), and Mozilla Firefox ESR (up to version 78.4).
How can CVE-2020-15969 be fixed?
To fix CVE-2020-15969, users should update their affected software to the latest available version provided by the respective vendors.
Where can I find more information about CVE-2020-15969?
You can find more information about CVE-2020-15969 on the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1666570), [usrsctp Commit](https://github.com/sctplab/usrsctp/commit/ffed0925f27d404173c1e3e750d818f432d2c019), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/).