KLA11325
Multiple vulnerabilities in Mozilla Firefox and Mozilla Firefox ESR
Updated: 05/22/2020
Detect date
?
10/02/2018
Severity
?
Critical
Description

Multiple serious vulnerabilities were found in Mozilla Firefox and Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A vulnerability in register allocation in JavaScript can be exploited remotely via arbitrary reading and writing to execute arbitrary code;
  2. A vulnerability related to JavaScript JIT compiler can be exploited remotely to bypass security restrictions.

Technical details

Vulnerability (2) results from memory leaks that occur when JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout.

Affected products

Mozilla Firefox earlier than 62.0.3
Mozilla Firefox ESR 60 earlier than 60.2.2

Solution

Update to the latest version
Download Mozilla Firefox

Original advisories

Mozilla Foundation Security Advisory 2018-24

Impacts
?
ACE 
[?]

SB 
[?]
Related products
Mozilla Firefox
Mozilla Firefox ESR
CVE-IDS
?
CVE-2018-123867.5Critical
CVE-2018-123879.1Critical