CVE-2020-6821 Information
Feb 14, 2021
cve
Description
When reading from areas partially or fully outside the source resource with WebGL’s codecopyTexSubImage/code method the specification requires the returned values be zero. Previously this memory was uninitialized leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird 68.7.0 Firefox ESR 68.7 and Firefox 75.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://bugzilla.mozilla.org/show_bug.cgi?id=1625404 https://usn.ubuntu.com/4335-1/ https://www.mozilla.org/security/advisories/mfsa2020-12/ https://www.mozilla.org/security/advisories/mfsa2020-13/ https://www.mozilla.org/security/advisories/mfsa2020-14/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: