Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4495

Опубликовано: 08 авг. 2015
Источник: debian

Описание

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselfixed38.1.1esr-1package
iceweaselnot-affectedjessiepackage
iceweaselnot-affectedwheezypackage
iceweaselnot-affectedsqueezepackage
pdf.jsfixed1.1.366+dfsg-1package
pdf.jsfixed1.0.907+dfsg-1+deb8u1jessiepackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2015-78/

  • for jessie: xul-ext-pdf.js binary package build was removed

  • https://github.com/mozilla/pdf.js/commit/0b5330781c367fcbc997947adbf2bdcdf71f61bc

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1179262

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

redhat
около 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

CVSS3: 8.8
nvd
около 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

suse-cvrf
около 10 лет назад

Security update for MozillaFirefox

suse-cvrf
около 10 лет назад

Security update for MozillaFirefox