CVE-2020-15678 log

Source
Severity Medium
Remote No
Type Denial of service
Description
A use-after-free issue has been found in Firefox before 81.0 where, when recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules.
Group Package Affected Fixed Severity Status Ticket
AVG-1235 firefox 80.0.1-1 81.0-1 High Fixed
Date Advisory Group Package Severity Type
23 Sep 2020 ASA-202009-10 AVG-1235 firefox High multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2020-42/#CVE-2020-15678
https://bugzilla.mozilla.org/show_bug.cgi?id=1660211