Уязвимость аварийного завершения работы в Mozilla Firefox и Thunderbird из-за логической ошибки
Описание
Возможность вызова аварийного завершения работы (crash) при обработке веб-контента. Проблема исходит из логической ошибки, когда ErrorResult ссылается на неинициализированную память. Данное аварийное завершение работы может быть использовано злоумышленником для эксплуатации.
Затронутые версии ПО
- Firefox до версии 52
- Firefox ESR до версии 45.8
- Thunderbird до версии 52
- Thunderbird до версии 45.8
Тип уязвимости
Аварийное завершение работы (crash)
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
A crash triggerable by web content in which an "ErrorResult" reference ...
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2