CVE-2020-6822Out-of-bounds Write in Mozilla Firefox

Severity
8.8HIGHNVD
OSV7.5OSV6.5
EPSS
0.8%
top 25.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 24

Description

On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified75
NVDmozilla/firefox< 75.0
CVEListV5mozilla/firefox_esrunspecified68.7
NVDmozilla/firefox_esr< 68.7.0
Ubuntumozilla/firefox< 75.0+build3-0ubuntu0.16.04.1+1

🔴Vulnerability Details

6
GHSA
GHSA-v2mh-4gcf-6ghr: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData2022-05-24
OSV
CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData2020-04-24
CVEList
CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData2020-04-24
OSV
thunderbird vulnerabilities2020-04-21
OSV
thunderbird vulnerabilities2020-04-13

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2020-04-21
Ubuntu
Thunderbird vulnerabilities2020-04-13
Red Hat
Mozilla: Out of bounds write in GMPDecodeData when processing large images2020-04-08
Ubuntu
Firefox vulnerabilities2020-04-07
Debian
CVE-2020-6822: firefox - On 32-bit builds, an out of bounds write could have occurred when processing an ...2020

💬Community

1
Bugzilla
CVE-2020-6822 Mozilla: Out of bounds write in GMPDecodeData when processing large images2020-04-07
CVE-2020-6822 — Out-of-bounds Write in Mozilla Firefox | cvebase