Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ use-after-free Π² ΡΠ΅Π°Π»ΠΈΠ·Π°ΡΠΈΠΈ WebGL, ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ ΡΠ΄Π°Π»Π΅Π½Π½ΠΎ Π²ΡΠΏΠΎΠ»Π½ΠΈΡΡ ΠΏΡΠΎΠΈΠ·Π²ΠΎΠ»ΡΠ½ΡΠΉ ΠΊΠΎΠ΄ Π² Mozilla Firefox, Thunderbird ΠΈ SeaMonkey
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
Use-after-free ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΡ Π±ΡΠ»Π° ΠΎΠ±Π½Π°ΡΡΠΆΠ΅Π½Π° Π² ΡΠ΅Π°Π»ΠΈΠ·Π°ΡΠΈΠΈ WebGL, ΡΡΠΎ ΠΏΠΎΠ·Π²ΠΎΠ»ΡΠ΅Ρ Π·Π»ΠΎΡΠΌΡΡΠ»Π΅Π½Π½ΠΈΠΊΡ Π²ΡΠΏΠΎΠ»Π½ΠΈΡΡ ΠΏΡΠΎΠΈΠ·Π²ΠΎΠ»ΡΠ½ΡΠΉ ΠΊΠΎΠ΄. ΠΡΠ° ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΡΠ²ΡΠ·Π°Π½Π° Ρ ΡΠ΄Π°Π»Π΅Π½ΠΈΠ΅ΠΌ ΡΡΠ°Π³ΠΌΠ΅Π½ΡΠ½ΠΎΠ³ΠΎ ΡΠ΅ΠΉΠ΄Π΅ΡΠ° ΡΠ΅ΡΠ΅Π· Π΅Π³ΠΎ Π°ΠΊΡΠ΅ΡΡΠΎΡ.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ Π²Π΅ΡΡΠΈΠΈ ΠΠ
- Mozilla Firefox Π΄ΠΎ Π²Π΅ΡΡΠΈΠΈ 15.0
- Mozilla Firefox ESR 10.x Π΄ΠΎ Π²Π΅ΡΡΠΈΠΈ 10.0.7
- Mozilla Thunderbird Π΄ΠΎ Π²Π΅ΡΡΠΈΠΈ 15.0
- Mozilla Thunderbird ESR 10.x Π΄ΠΎ Π²Π΅ΡΡΠΈΠΈ 10.0.7
- Mozilla SeaMonkey Π΄ΠΎ Π²Π΅ΡΡΠΈΠΈ 2.12
Π’ΠΈΠΏ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ
Π£Π΄Π°Π»Π΅Π½Π½ΠΎΠ΅ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΠ΅ ΠΏΡΠΎΠΈΠ·Π²ΠΎΠ»ΡΠ½ΠΎΠ³ΠΎ ΠΊΠΎΠ΄Π°
Π‘ΡΡΠ»ΠΊΠΈ
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfThird Party Advisory
- Issue TrackingVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
Π£ΡΠ·Π²ΠΈΠΌΡΠ΅ ΠΊΠΎΠ½ΡΠΈΠ³ΡΡΠ°ΡΠΈΠΈ
ΠΠ΄Π½ΠΎ ΠΈΠ·
ΠΠ΄Π½ΠΎ ΠΈΠ·
ΠΠ΄Π½ΠΎ ΠΈΠ·
ΠΠ΄Π½ΠΎ ΠΈΠ·
EPSS
10 Critical
CVSS2
ΠΠ΅ΡΠ΅ΠΊΡΡ
Π‘Π²ΡΠ·Π°Π½Π½ΡΠ΅ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ
Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via vectors related to deletion of a fragment shader by its accessor.
Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via vectors related to deletion of a fragment shader by its accessor.
Use-after-free vulnerability in the WebGL implementation in Mozilla Fi ...
Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via vectors related to deletion of a fragment shader by its accessor.
ELSA-2012-1211: thunderbird security update (CRITICAL)
EPSS
10 Critical
CVSS2