CVE-2020-26952 - log back

CVE-2020-26952 edited at 18 Nov 2020 07:58:33
Severity
- Medium
+ High
Type
- Information disclosure
+ Arbitrary code execution
CVE-2020-26952 edited at 18 Nov 2020 07:57:44
Description
- An information disclosure issue has been found in Firefox before 83.0. When drawing a transparent image on top of an unknown cross-origin image, the Skia library drawImage function took a variable amount of time depending on the content of the underlying image. This resulted in potential cross-origin information exposure of image content through timing side-channel attacks.
+ A security issue has been found in Firefox before 83.0 where incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handling out-of-memory errors.
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/#CVE-2020-16012
+ https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/#CVE-2020-26952
- https://bugzilla.mozilla.org/show_bug.cgi?id=1642028
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1667685
CVE-2020-26952 edited at 17 Nov 2020 18:33:48
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ An information disclosure issue has been found in Firefox before 83.0. When drawing a transparent image on top of an unknown cross-origin image, the Skia library drawImage function took a variable amount of time depending on the content of the underlying image. This resulted in potential cross-origin information exposure of image content through timing side-channel attacks.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/#CVE-2020-16012
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1642028
Notes
CVE-2020-26952 created at 17 Nov 2020 18:15:06