Mozilla Firefox等都是美国Mozilla基金会的产品。Mozilla Firefox是一款开源Web浏览器。Mozilla Firefox ESR是Firefox(Web浏览器)的一个延长支持版本。Mozilla Thunderbird是一套从Mozilla Application Suite独立出来的电子邮件客户端软件。
基于Windows平台的Mozilla Firefox 79之前版本、Firefox ESR 78.1之前版本和Thunderbird 78.1之前版本中存在安全漏洞。攻击者可通过向安装路径中放入恶意文件利用该漏洞使浏览器从安装目录中加载DLL文件。
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-30/
https://www.mozilla.org/en-US/security/advisories/mfsa2020-32/
https://www.mozilla.org/en-US/security/advisories/mfsa2020-33/
来源:MISC
链接:https://www.mozilla.org/security/advisories/mfsa2020-32/
来源:MISC
链接:https://www.mozilla.org/security/advisories/mfsa2020-33/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.html
来源:MISC
链接:https://www.mozilla.org/security/advisories/mfsa2020-30/
来源:MISC
链接:https://bugzilla.mozilla.org/show_bug.cgi?id=1644954
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-15657
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2724/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Mozilla-Firefox-multiple-vulnerabilities-32927
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2580/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2640/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2675/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2851/