Multiple vulnerabilities in Mozilla Firefox and Mozilla Firefox ESR

Обновлено: 03/06/2020
Дата обнаружения
Уровень угрозы

Multiple serious vulnerabilities were found in Mozilla Firefox and Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A vulnerability in register allocation in JavaScript can be exploited remotely via arbitrary reading and writing to execute arbitrary code;
  2. A vulnerability related to JavaScript JIT compiler can be exploited remotely to bypass security restrictions.

Technical details

Vulnerability (2) results from memory leaks that occur when JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout.

Пораженные продукты

Mozilla Firefox earlier than 62.0.3
Mozilla Firefox ESR 60 earlier than 60.2.2


Update to the latest version
Download Mozilla Firefox

Первичный источник обнаружения
Mozilla Foundation Security Advisory 2018-24
Оказываемое влияние

Связанные продукты
Mozilla Firefox
Mozilla Firefox ESR
