Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9797

Опубликовано: 26 апр. 2019
Источник: debian
EPSS Низкий

Описание

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed66.0-1package
firefox-esrfixed60.7.0esr-1package
thunderbirdfixed1:60.7.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-07/#CVE-2019-9797

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/#CVE-2019-9797

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-15/#CVE-2019-9797

EPSS

Процентиль: 65%
0.00498
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

CVSS3: 5.3
redhat
около 6 лет назад

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

CVSS3: 5.3
nvd
больше 6 лет назад

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

CVSS3: 5.3
github
около 3 лет назад

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

CVSS3: 5.3
fstec
около 6 лет назад

Уязвимость функции createImageBitmap браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибкой подтверждения источника данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 65%
0.00498
Низкий