Уязвимость выполнения произвольного кода в Mozilla Firefox и Thunderbird из-за повреждения памяти
Описание
В браузерах Firefox версии 49 и Firefox ESR 45.4 были обнаружены ошибки безопасности, связанные с безопасностью памяти. Некоторые из этих ошибок демонстрируют признаки повреждения памяти. Считается, что при достаточных усилиях они способны позволить злоумышленнику выполнить произвольный код.
Затронутые версии ПО
- Thunderbird < 45.5
- Firefox ESR < 45.5
- Firefox < 50
Тип уязвимости
- Повреждение памяти
- Выполнение произвольного кода
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. S ...
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2