Back

CVE-2020-6831

CRITICAL

A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

Published: May 26, 2020 Modified: Jun 17, 2026
CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (10)

Vendor Product Version
mozilla firefox * < 76.0
mozilla firefox_esr * < 68.8.0
mozilla thunderbird * < 68.8.0
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
canonical ubuntu_linux 19.10
canonical ubuntu_linux 20.04
debian debian_linux 9.0
debian debian_linux 10.0
opensuse leap 15.2

GitHub Security Advisory GHSA-5x26-44w7-97vc

A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.80%

Top 7% most likely to be exploited

Threat Score 40.9 / 100

Data Sources

NVD EPSS GitHub