CVE-2020-12420
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
References
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1643437https://security.gentoo.org/glsa/202007-09https://security.gentoo.org/glsa/202007-10https://usn.ubuntu.com/4421-1/https://www.mozilla.org/security/advisories/mfsa2020-24/https://www.mozilla.org/security/advisories/mfsa2020-25/https://www.mozilla.org/security/advisories/mfsa2020-26/