Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9811

Опубликовано: 23 июл. 2019
Источник: debian
EPSS Низкий

Описание

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed68.0-1package
firefox-esrfixed60.8.0esr-1package
thunderbirdfixed1:60.8.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-9811

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-9811

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-23/#CVE-2019-9811

EPSS

Процентиль: 72%
0.00733
Низкий

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 6 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 7.5
redhat
больше 6 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.3
nvd
больше 6 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.3
github
больше 3 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.3
fstec
больше 6 лет назад

Уязвимость браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, связанная с недостатками разграничения доступа, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00733
Низкий