CVE-2020-12387 log

Source
Severity Critical
Remote Yes
Type Arbitrary code execution
Description
A race condition has been found in Firefox before 76.0 and Thunderbird before 68.8.0, when running shutdown code for Web Worker, leading to a use-after-free vulnerability. This results in a potentially exploitable crash.
Group Package Affected Fixed Severity Status Ticket
AVG-1155 thunderbird 68.7.0-2 68.8.0-1 Critical Fixed
AVG-1148 firefox 75.0-1 76.0-1 Critical Fixed
Date Advisory Group Package Severity Type
09 May 2020 ASA-202005-7 AVG-1155 thunderbird Critical multiple issues
06 May 2020 ASA-202005-3 AVG-1148 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2020-16/#CVE-2020-12387
https://www.mozilla.org/en-US/security/advisories/mfsa2020-18/#CVE-2020-12387
https://bugzilla.mozilla.org/show_bug.cgi?id=1545345