Vulnerability CVE-2020-15668: Information

Description

A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Published: Oct. 1, 2020
Modified: Oct. 2, 2020
Error type identifier: CWE-667

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1651520
  • Issue Tracking
  • Permissions Required
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2020-36/
  • Release Notes
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2020-39/
  • Release Notes
  • Vendor Advisory
    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*
      End excliding
      80.0

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:-:*:*
      End excliding
      80.0