Out of bounds reads vulnerability in Google Chrome, Microsoft Edge and Mozilla Firefox - CVE-2019-20503ID: oval:org.secpod.oval:def:61973 | Date: (C)2020-03-12 (M)2024-03-27 |
Class: VULNERABILITY | Family: windows |
Mozilla Firefox 74, Mozilla Firefox ESR 68.6, Mozilla Thunderbird 68.6, Google Chrome 80.0.3987.149 and Microsoft Edge 80.0.3987.149: The inputs to sctp_load_addresses_from_init are verified by sctp_arethere_unrecognized_parameters however, the two functions handled parameter bounds differently, resulting in out of bounds reads when parameters are partially outside a chunk.
Platform: |
Microsoft Windows Server 2022 |
Microsoft Windows 11 |
Microsoft Windows Server 2008 |
Microsoft Windows 7 |
Microsoft Windows 8.1 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2016 |
Microsoft Windows Server 2019 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows 10 |
Product: |
Mozilla Firefox |
Mozilla Firefox ESR |
Mozilla Thunderbird |
Google Chrome |
Google Chrome Enterprise |
Microsoft Edge (Chromium-based) |
Microsoft Edge Business (Chromium-based) |