Rule Category

BROWSER-FIREFOX -- Snort has detected traffic known to exploit vulnerabilities present in the Firefox browser, or products that have the "Gecko" engine (Thunderbird email client, etc.).

Alert Message

BROWSER-FIREFOX Mozilla Firefox ReadableStreamCloseInternal out-of-bounds access attempt

Rule Explanation

This rule looks for a certain sequence of JavaScript operations that are designed to cause a state inconsistency bug to manifest, leading to an out-of-bounds read. This bug could be exploited to corrupt memory, potentially leading to arbitrary remote code execution.

What To Look For

This rule alerts when a specifically formatted web page designed to exploit CVE-2020-6806 is detected. CVE-2020-6806 is a memory corruption bug in Mozilla Firefox.

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

MITRE ATT&CK Framework

Tactic: Initial Access

Technique: Drive-by Compromise

For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org

Additional Links

Rule Vulnerability

CVE Additional Information