CVE-2020-26974 - log back

CVE-2020-26974 edited at 15 Dec 2020 17:22:49
Description
- A security issue was found in Firefox before 84.0. When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash.
+ A security issue was found in Firefox before 84.0 and Thunderbird before 78.6. When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash.
References
https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/#CVE-2020-26974
+ https://www.mozilla.org/en-US/security/advisories/mfsa2020-56/#CVE-2020-26974
https://bugzilla.mozilla.org/show_bug.cgi?id=1681022
CVE-2020-26974 edited at 15 Dec 2020 16:56:36
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ A security issue was found in Firefox before 84.0. When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/#CVE-2020-26974
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1681022
Notes
CVE-2020-26974 created at 15 Dec 2020 16:48:51