KLA11416
Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
Обновлено: 26/06/2019
Дата обнаружения
12/02/2019
Уровень угрозы
High
Описание

Multiple serious vulnerabilities were found in Mozilla Firefox and Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An use-after-free vulnerability in Skia can be exploited remotely via specially crafted website to execute arbitrary code;
  2. An integer overflow vulnerability in Skia can be exploited remotely via specially crafted website to cause denial of service;
  3. A cross-origin theft of images issue in ImageBitmapRenderingContext can be exploited to bypass security restrictions
  4. A buffer overflow vulnerability in Skia can be exploited remotely via specially crafted website to cause denial of service;

Technical details

Vulnerability (3) only affects Firefox 65.

Vulnerability (4) only affects Firefox ESR on macOS

Пораженные продукты

Mozilla Firefox earlier than 65.0.1
Mozilla Firefox ESR earlier than 60.5.1

Решение

Update to the latest version
Download Mozilla Firefox

Первичный источник обнаружения
Mozilla Foundation Security Advisory 2019-04
Mozilla Foundation Security Advisory 2019-05
Оказываемое влияние
?
OSI 
[?]

DoS 
[?]
Связанные продукты
Mozilla Firefox
Mozilla Firefox ESR
CVE-IDS