Back
CVE-2020-6831
CRITICAL
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Published: May 26, 2020
Modified: Jun 17, 2026
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (10)
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | * < 76.0 |
| mozilla | firefox_esr | * < 68.8.0 |
| mozilla | thunderbird | * < 68.8.0 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.10 |
| canonical | ubuntu_linux | 20.04 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| opensuse | leap | 15.2 |
GitHub Security Advisory GHSA-5x26-44w7-97vc
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have...
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00000.html Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/158480/usrsctp-Stack-Buffer-Overflow.html Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1632241 Permissions Required
- https://security.gentoo.org/glsa/202005-03 Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202005-04 Third Party Advisory
- https://usn.ubuntu.com/4373-1/ Third Party Advisory
- https://www.debian.org/security/2020/dsa-4714 Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-16/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-17/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-18/ Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00000.html Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/158480/usrsctp-Stack-Buffer-Overflow.html Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1632241 Permissions Required
- https://security.gentoo.org/glsa/202005-03 Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202005-04 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
5.80%
Top 7% most likely to be exploited
Threat Score
40.9 / 100
Data Sources
NVD
EPSS
GitHub