Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17026

Опубликовано: 02 мар. 2020
Источник: debian

Описание

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed72.0.1-1package
firefox-esrfixed68.4.1esr-1package
thunderbirdfixed1:68.4.1-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/#CVE-2019-17026

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-04/#CVE-2019-17026

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
redhat
около 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
nvd
почти 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
github
больше 3 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
fstec
около 6 лет назад

Уязвимость JIT-компилятора IonMonkey браузеров Firefox и Firefox ESR, связанная с доступом к ресурсу через несовместимые типы, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

Уязвимость CVE-2019-17026