CVE-2020-6821
24.04.2020, 16:15
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 75.0 |
mozilla | firefox_esr | 𝑥 < 68.7.0 |
mozilla | thunderbird | 𝑥 < 68.7.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
firefox-esr |
| ||||||||||||
thunderbird |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||||||||||||
mozjs38 |
| ||||||||||||||||||||||||||
mozjs52 |
| ||||||||||||||||||||||||||
mozjs60 |
| ||||||||||||||||||||||||||
mozjs68 |
| ||||||||||||||||||||||||||
thunderbird |
|
Common Weakness Enumeration
References