CVE Vulnerabilities

CVE-2020-6821

Use of Uninitialized Resource

Published: Apr 24, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

When reading from areas partially or fully outside the source resource with WebGLs copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 75.0 (excluding)
Firefox_esr Mozilla * 68.7.0 (excluding)
Thunderbird Mozilla * 68.7.0 (excluding)

Potential Mitigations

References