CVE-2020-6821 log

Source
Severity High
Remote Yes
Type Information disclosure
Description
An information disclosure issue has been found in Firefox before 75.0 and Thunderbird before 68.7.0. When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure.
Group Package Affected Fixed Severity Status Ticket
AVG-1132 thunderbird 68.6.0-2 68.7.0-1 Critical Fixed
AVG-1127 firefox 74.0.1-1 75.0-1 Critical Fixed
Date Advisory Group Package Severity Type
08 Apr 2020 ASA-202004-8 AVG-1127 firefox Critical multiple issues
13 Apr 2020 ASA-202004-12 AVG-1132 thunderbird Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2020-12/#CVE-2020-6821
https://bugzilla.mozilla.org/show_bug.cgi?id=1625404