KLA11325
Multiple vulnerabilities in Mozilla Firefox and Mozilla Firefox ESR
Обновлено: 26/06/2019
Дата обнаружения
02/10/2018
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities were found in Mozilla Firefox and Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A vulnerability in register allocation in JavaScript can be exploited remotely via arbitrary reading and writing to execute arbitrary code;
  2. A vulnerability related to JavaScript JIT compiler can be exploited remotely to bypass security restrictions.

Technical details

Vulnerability (2) results from memory leaks that occur when JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout.

Пораженные продукты

Mozilla Firefox earlier than 62.0.3
Mozilla Firefox ESR 60 earlier than 60.2.2

Решение

Update to the latest version
Download Mozilla Firefox

Первичный источник обнаружения
Mozilla Foundation Security Advisory 2018-24
Оказываемое влияние
?
ACE 
[?]

SB 
[?]
Связанные продукты
Mozilla Firefox
Mozilla Firefox ESR
CVE-IDS
CVE-2018-123867.5Critical
CVE-2018-123879.1Critical