CVE-2020-12407

Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content. This vulnerability affects Firefox < 77.
References
Link Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1637112 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2020-20/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1637112 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2020-20/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:59

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1637112 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1637112 - Issue Tracking, Permissions Required, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2020-20/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2020-20/ - Vendor Advisory

Information

Published : 2020-07-09 15:15

Updated : 2024-11-21 04:59


NVD link : CVE-2020-12407

Mitre link : CVE-2020-12407

CVE.ORG link : CVE-2020-12407


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-125

Out-of-bounds Read