CVE-2020-6821Use of Uninitialized Resource in Mozilla Firefox

Severity
7.5HIGHNVD
OSV8.8OSV6.5
EPSS
0.5%
top 32.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 24

Description

When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified75
NVDmozilla/firefox< 75.0
CVEListV5mozilla/firefox_esrunspecified68.7
NVDmozilla/firefox_esr< 68.7.0
Ubuntumozilla/firefox< 75.0+build3-0ubuntu0.16.04.1+1

🔴Vulnerability Details

6
GHSA
GHSA-jj5p-vxx9-rvj7: When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned va2022-05-24
CVEList
CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned va2020-04-24
OSV
CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned va2020-04-24
OSV
thunderbird vulnerabilities2020-04-21
OSV
thunderbird vulnerabilities2020-04-13

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2020-04-21
Ubuntu
Thunderbird vulnerabilities2020-04-13
Red Hat
Mozilla: Uninitialized memory could be read when using the WebGL copyTexSubImage method2020-04-08
Ubuntu
Firefox vulnerabilities2020-04-07
Debian
CVE-2020-6821: firefox - When reading from areas partially or fully outside the source resource with WebG...2020

💬Community

1
Bugzilla
CVE-2020-6821 Mozilla: Uninitialized memory could be read when using the WebGL copyTexSubImage method2020-04-07
CVE-2020-6821 — Use of Uninitialized Resource | cvebase