Description:
Mozilla has published two security advisories (MFSA 2020-42 and MFSA 2020-43) to address multiple vulnerabilities in Firefox browser. A remote attacker could entice a user running a vulnerable browser to visit a web page with specially crafted content to exploit the vulnerabilities.
Affected Systems:
- Firefox ESR prior to version 78.3
- Firefox prior to version 81
Impact:
Successful exploitation of the vulnerabilities could lead to arbitrary code execution, cross site scripting, spoofing or application crash on an affected system.
Recommendation:
Mozilla has released new versions of the product to address the issues and they can be downloaded at the following URLs:
- Firefox 81 for Windows, Macintosh and Linux
https://www.mozilla.org/en-US/firefox/all/
- Firefox ESR 78.3 for Windows, Macintosh and Linux
https://www.mozilla.org/en-US/firefox/organizations/all/
Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
More Information:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-42/
https://www.mozilla.org/en-US/security/advisories/mfsa2020-43/
https://www.hkcert.org/my_url/en/alert/20092302
https://us-cert.cisa.gov/ncas/current-activity/2020/09/22/mozilla-releases-security-updates-firefox-and-firefox-esr
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15673 (to CVE-2020-15678)