Уязвимость типа "использование после освобождения" (use-after-free) в Thunderbird, Firefox и Firefox ESR при манипуляции DOM содержимым SVG, обнаруженная методом фаззинга
Описание
В процессе манипуляции DOM содержимым SVG была выявлена уязвимость типа "использование после освобождения" (use-after-free). Данная проблема была обнаружена с использованием метода фаззинга.
Затронутые версии ПО
- Thunderbird версии ниже 45.7
- Firefox ESR версии ниже 45.7
- Firefox версии ниже 51
Тип уязвимости
Уязвимость типа "использование после освобождения" (use-after-free)
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
A potential use-after-free found through fuzzing during DOM manipulati ...
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2