漏洞信息详情
Mozilla Firefox和Firefox ESR 代码问题漏洞
漏洞简介
Mozilla Firefox和Mozilla Firefox ESR都是美国Mozilla基金会的产品。Mozilla Firefox是一款开源Web浏览器。Mozilla Firefox ESR是Firefox(Web浏览器)的一个延长支持版本。
Mozilla Firefox 67.0.3之前版本和Firefox ESR 60.7.1之前版本中的Array.pop文件存在类型混淆漏洞。攻击者可利用该漏洞造成拒绝服务(崩溃)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/
参考网址
来源:www.mozilla.org
链接:https://www.mozilla.org/en-US/security/advisories/mfsa2019-18
来源:www.mozilla.com
链接:http://www.mozilla.com/en-US/
来源:MISC
链接:https://www.mozilla.org/security/advisories/mfsa2019-20/
来源:MISC
链接:https://bugzilla.mozilla.org/show_bug.cgi?id=1544386
来源:MISC
链接:https://www.mozilla.org/security/advisories/mfsa2019-18/
来源:GENTOO
链接:https://security.gentoo.org/glsa/201908-12
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/4020-1/
来源:www.debian.org
链接:http://www.debian.org/security/2019/dsa-4466
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1626
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1624
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1623
来源:lists.debian.org
链接:https://lists.debian.org/debian-lts-announce/2019/06/msg00015.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Firefox-memory-corruption-via-Array-pop-29559
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2195/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2327/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/153353/Ubuntu-Security-Notice-USN-4020-1.html
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/108810
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2158/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/1127577
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2215/
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/47038
受影响实体
暂无
补丁
- Mozilla Firefox和Mozilla Firefox ESR 安全漏洞的修复措施<!--2019-6-19-->
还没有评论,来说两句吧...