CVE-2020-6806: High severity Mozilla Firefox vulnerability
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6806?
CVE-2020-6806 is a vulnerability in Mozilla Firefox and Thunderbird that allows for an out-of-bounds read off the end of an array during script execution, potentially leading to memory corruption and a crash.
How does CVE-2020-6806 affect Mozilla Firefox and Thunderbird?
CVE-2020-6806 affects Mozilla Firefox versions up to 74, Mozilla Thunderbird versions up to 68.6, and Mozilla Firefox ESR versions up to 68.6.
What is the severity of CVE-2020-6806?
CVE-2020-6806 has a severity rating of high (7) based on the Common Vulnerability Scoring System (CVSS).
How can I fix CVE-2020-6806?
To fix CVE-2020-6806, upgrade Mozilla Firefox to version 74 or later, Mozilla Thunderbird to version 68.6 or later, or Mozilla Firefox ESR to version 68.6 or later.
Where can I find more information about CVE-2020-6806?
You can find more information about CVE-2020-6806 on the Mozilla Bugzilla and Mozilla security advisories pages.