Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-15667
HistoryOct 01, 2020 - 7:15 p.m.

Design/Logic Flaw

2020-10-0119:15:00
PRIOn knowledge base
www.prio-n.com
5

8.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.5%

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.

CPENameOperatorVersion
firefoxlt80.0

8.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.5%