VDB

CVE-2020-6799

CVE-2020-6799 PUBLISHED

Reported by mozilla · Published March 2, 2020

Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party application that insufficiently sanitized URL data. In that situation, clicking a link in the third party application could have been used to retrieve and execute files whose location was supplied through command line arguments. Note: This issue only affects Windows operating systems and when Firefox is configured as the default handler for non-default filetypes. Other operating systems are unaffected. This vulnerability affects Firefox < 73 and Firefox < ESR68.5.

Affected Products

VendorProductVersions
MozillaFirefoxunspecified, unspecified
alpinefirefox-esr0, 0, 0
MozillaFirefoxunspecified, unspecified

Timeline

  • Feb 18, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score

References

  • x_refsource_MISC
  • x_refsource_MISC
  • x_refsource_MISC
  • GLSA-202003-02 vendor-advisoryx_refsource_GENTOO
Open in Interactive Console →
$ Console Community · 100/wk Open console ›