{"id":"MGASA-2020-0163","summary":"Updated firefox packages fix security vulnerabilities","details":"Updated firefox packages fix security vulnerabilities:\n\nWhen reading from areas partially or fully outside the source resource\nwith WebGL's copyTexSubImage method, the specification requires the\nreturned values be zero. Previously, this memory was uninitialized,\nleading to potentially sensitive data disclosure (CVE-2020-6821).\n\nOn 32-bit builds, an out of bounds write could have occurred when\nprocessing an image larger than 4 GB in GMPDecodeData. It is possible\nthat with enough effort this could have been exploited to run arbitrary\ncode (CVE-2020-6822).\n\nMozilla developers Tyson Smith and Christian Holler reported memory safety\nbugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed\nevidence of memory corruption and we presume that with enough effort some\nof these could have been exploited to run arbitrary code (CVE-2020-6825).\n","modified":"2026-04-16T00:09:24.635053007Z","published":"2020-04-08T17:12:00Z","upstream":["CVE-2020-6821","CVE-2020-6822","CVE-2020-6825"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0163.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26442"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2020-13/"}],"affected":[{"package":{"name":"firefox","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"68.7.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0163.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"68.7.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0163.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}