Уязвимость типа "использование после освобождения" (use-after-free) в SVG-анимации в Firefox и Tor Browser на Windows
Описание
Обнаружена уязвимость типа "использование после освобождения" в анимации SVG. Эксплуатация этой уязвимости была выявлена в реальных условиях и нацелена на пользователей Firefox и Tor Browser на Windows.
Затронутые версии ПО
- Firefox версий до 50.0.2
- Firefox ESR версий до 45.5.1
- Thunderbird версий до 45.5.1
Тип уязвимости
Уязвимость типа "использование после освобождения" (use-after-free)
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Одно из
Одновременно
Одновременно
Одновременно
Одновременно
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
A use-after-free vulnerability in SVG Animation has been discovered. A ...
EPSS
7.5 High
CVSS3
5 Medium
CVSS2