Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 734980 (CVE-2020-15652, CVE-2020-6463) - [Tracker] Multiple vulnerabilities in Mozilla products (CVE-2020-15652, CVE-2020-6463)
Summary: [Tracker] Multiple vulnerabilities in Mozilla products (CVE-2020-15652, CVE-2...
Status: RESOLVED FIXED
Alias: CVE-2020-15652, CVE-2020-6463
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on: CVE-2020-15659, MFSA-2020-30, MFSA-2020-31 MFSA-2020-35
Blocks:
  Show dependency tree
 
Reported: 2020-07-31 17:22 UTC by Sam James
Modified: 2020-07-31 19:06 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-31 17:22:38 UTC
* CVE-2020-15652

Description:
"By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script."

* CVE-2020-6463

Description:
"Crafted media files could lead to a race in texture caches, resulting in a use-after-free, memory corruption, and a potentially exploitable crash."