漏洞信息详情

Mozilla Firefox和Firefox ESR 代码问题漏洞

漏洞简介

Mozilla Firefox和Mozilla Firefox ESR都是美国Mozilla基金会的产品。Mozilla Firefox是一款开源Web浏览器。Mozilla Firefox ESR是Firefox(Web浏览器)的一个延长支持版本。

Mozilla Firefox 67.0.3之前版本和Firefox ESR 60.7.1之前版本中的Array.pop文件存在类型混淆漏洞。攻击者可利用该漏洞造成拒绝服务(崩溃)。

漏洞公告

目前厂商已发布升级补丁以修复漏洞,补丁获取链接:

https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/

参考网址

来源:www.mozilla.org

链接:https://www.mozilla.org/en-US/security/advisories/mfsa2019-18

来源:www.mozilla.com

链接:http://www.mozilla.com/en-US/

来源:MISC

链接:https://www.mozilla.org/security/advisories/mfsa2019-20/

来源:MISC

链接:https://bugzilla.mozilla.org/show_bug.cgi?id=1544386

来源:MISC

链接:https://www.mozilla.org/security/advisories/mfsa2019-18/

来源:GENTOO

链接:https://security.gentoo.org/glsa/201908-12

来源:usn.ubuntu.com

链接:https://usn.ubuntu.com/4020-1/

来源:www.debian.org

链接:http://www.debian.org/security/2019/dsa-4466

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:1626

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:1624

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:1623

来源:lists.debian.org

链接:https://lists.debian.org/debian-lts-announce/2019/06/msg00015.html

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Firefox-memory-corruption-via-Array-pop-29559

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2195/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2327/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/153353/Ubuntu-Security-Notice-USN-4020-1.html

来源:www.securityfocus.com

链接:https://www.securityfocus.com/bid/108810

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2158/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2215/

来源:www.exploit-db.com

链接:https://www.exploit-db.com/exploits/47038

受影响实体

    暂无


漏洞信息快速查询

相关漏洞

更多