CVE-2020-15664
Publication date 26 August 2020
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 24.04 LTS noble |
Fixed 80.0.1+build1-0ubuntu1
|
22.04 LTS jammy |
Fixed 80.0.1+build1-0ubuntu1
|
|
20.04 LTS focal |
Fixed 80.0+build2-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Fixed 80.0+build2-0ubuntu0.18.04.1
|
|
16.04 LTS xenial |
Fixed 80.0+build2-0ubuntu0.16.04.1
|
|
14.04 LTS trusty | Not in release | |
firefox-esr | 24.04 LTS noble | Not in release |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
mozjs38 | 24.04 LTS noble | Not in release |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
mozjs52 | 24.04 LTS noble | Not in release |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Ignored | |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
mozjs60 | 24.04 LTS noble | Not in release |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
mozjs68 | 24.04 LTS noble | Not in release |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Ignored | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
thunderbird | 24.04 LTS noble |
Not affected
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Fixed 1:78.7.1+build1-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Fixed 1:78.8.1+build1-0ubuntu0.18.04.1
|
|
16.04 LTS xenial | Ignored end of standard support, was needed | |
14.04 LTS trusty | Not in release |
Notes
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-4474-1
- Firefox vulnerabilities
- 26 August 2020
Other references
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-36/#CVE-2020-15664
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-37/#CVE-2020-15664
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-40/#CVE-2020-15664
- https://rhn.redhat.com/errata/RHSA-2020-3558.html
- https://www.cve.org/CVERecord?id=CVE-2020-15664