Firefox 74.0.1
([Development] Apr 3, 2020 21:23 UTC (Fri) (ris))
- Reference: 0000816794
- News link: https://lwn.net/Articles/816794/
- Source link:
Firefox 74.0.1 has been [1]released with [2]two security fixes . CVE-2020-6819 is a use-after-free when running the nsDocShell destructor and CVE-2020-6820 is a use-after-free when handling a ReadableStream. In both cases there have been targeted attacks in the wild abusing these flaws. These issues have also been fixed in Firefox ESR 68.6.1.
[1] https://www.mozilla.org/en-US/firefox/74.0.1/releasenotes/
[2] https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/
[1] https://www.mozilla.org/en-US/firefox/74.0.1/releasenotes/
[2] https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/