A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
2020-01-08T20:15:12.703
2024-11-21T04:21:44.323
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 70.0 | Yes |
Application | mozilla | firefox_esr | < 68.2 | Yes |
Application | mozilla | thunderbird | < 68.2 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |