Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvcf-5p4m-53vh

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

EPSS

Процентиль: 29%
0.00107
Низкий

Связанные уязвимости

nvd
больше 12 лет назад

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

debian
больше 12 лет назад

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x befor ...

suse-cvrf
больше 12 лет назад

Security update for Mozilla Firefox

suse-cvrf
больше 12 лет назад

Security update for Mozilla Firefox

EPSS

Процентиль: 29%
0.00107
Низкий