CVE-2020-6805: Use After Free
Last updated 24 July 2024
Other sources
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 68.6 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 68.6 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 68.6 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 74 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 68.6 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 138.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.10.0esr-1~deb12u1Fixed in 128.9.0esr-2Fixed in 128.10.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:128.10.0esr-1~deb11u1Fixed in 1:128.8.0esr-1~deb12u1Fixed in 1:128.10.0esr-1~deb12u1Fixed in 1:128.9.0esr-1Fixed in 1:128.10.0esr-1 - Upgrade
Upgrade
Mozilla Thunderbird / Firefoxto a version that resolves this vulnerability.Fixed in 68.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6805?
CVE-2020-6805 is a vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird that could lead to a potentially exploitable crash.
How severe is CVE-2020-6805?
CVE-2020-6805 is classified as a high severity vulnerability with a severity value of 7.
Which software versions are affected by CVE-2020-6805?
Mozilla Firefox versions up to exclusive 74, Firefox ESR versions up to exclusive 68.6, and Thunderbird versions up to exclusive 68.6 are affected by CVE-2020-6805.
How can CVE-2020-6805 be fixed?
To fix CVE-2020-6805, users should update to the latest versions of Mozilla Firefox, Firefox ESR, or Thunderbird, which have the necessary security patches.
Where can I find more information about CVE-2020-6805?
More information about CVE-2020-6805 can be found in the Mozilla Bugzilla and Mozilla security advisories (MFSA2020-08 and MFSA2020-10) linked in the references.