ZeroHour

CVE-2020-6821

CVSS 3.1
7.5 high
EPSS
2%p73
Published
()
Modified
Description

When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

Vendors
mozilla
Products
firefox, firefox esr, thunderbird
Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news