{"id":"MGASA-2020-0141","summary":"Updated firefox packages fix security vulnerabilities","details":"Updated firefox packages fix security vulnerabilities:\n\nThe inputs to sctp_load_addresses_from_init are verified by\nsctp_arethere_unrecognized_parameters; however, the two functions\nhandled parameter bounds differently, resulting in out of bounds\nreads when parameters are partially outside a chunk (CVE-2019-20503).\n\nWhen removing data about an origin whose tab was recently closed,\na use-after-free could occur in the Quota manager, resulting in a\npotentially exploitable crash (CVE-2020-6805).\n\nBy carefully crafting promise resolutions, it was possible to cause an\nout-of-bounds read off the end of an array resized during script execution.\nThis could have led to memory corruption and a potentially exploitable\ncrash (CVE-2020-6806).\n\nWhen a device was changed while a stream was about to be destroyed, the\nstream-reinit task may have been executed after the stream was destroyed,\ncausing a use-after-free and a potentially exploitable crash\n(CVE-2020-6807).\n\nThe 'Copy as cURL' feature of Devtools' network tab did not properly escape\nthe HTTP method of a request, which can be controlled by the website. If a\nuser used the 'Copy as Curl' feature and pasted the command into a terminal,\nit could have resulted in command injection and arbitrary command execution\n(CVE-2020-6811).\n\nThe first time AirPods are connected to an iPhone, they become named after\nthe user's name by default (e.g. Jane Doe's AirPods.) Websites with camera\nor microphone permission are able to enumerate device names, disclosing the\nuser's name. To resolve this issue, Firefox added a special case that\nrenames devices containing the substring 'AirPods' to simply 'AirPods'\n(CVE-2020-6812).\n\nMozilla developers and community members Byron Campen, Jason Kratzer, and\nChristian Holler reported memory safety bugs present in Firefox 73 and\nFirefox ESR 68.5. Some of these bugs showed evidence of memory corruption\nand we presume that with enough effort some of these could have been\nexploited to run arbitrary code (CVE-2020-6814).\n\nnss has been updated to 3.51 fixing various bugs and crashes.\n","modified":"2026-02-04T04:28:05.104999Z","published":"2020-03-14T08:35:35Z","related":["CVE-2019-20503","CVE-2020-6805","CVE-2020-6806","CVE-2020-6807","CVE-2020-6811","CVE-2020-6812","CVE-2020-6814"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0141.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26325"},{"type":"REPORT","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2020-09/"},{"type":"REPORT","url":"https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.51_release_notes"}],"affected":[{"package":{"name":"firefox","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"68.6.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0141.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"68.6.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0141.json"}},{"package":{"name":"nss","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.51.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0141.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}