By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-6797.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "73.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "68.5.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "68.5.0"
}
]
}
]