Уязвимость выхода из песочницы в Mozilla Firefox и Thunderbird через установку вредоносного языкового пакета
Описание
Исследователь в рамках конкурса Pwn2Own продемонстрировал уязвимость выхода из песочницы путем установки вредоносного языкового пакета и открытия функции браузера, использующей компрометированный перевод.
Затронутые версии ПО
- Firefox ESR < 60.8
- Firefox < 68
- Thunderbird < 60.8
Тип уязвимости
Выход из песочницы
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Issue TrackingPermissions Required
- ExploitIssue TrackingPatchVendor Advisory
- ExploitIssue TrackingVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
8.3 High
CVSS3
5.1 Medium
CVSS2
Дефекты
Связанные уязвимости
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbo ...
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Уязвимость браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, связанная с недостатками разграничения доступа, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
8.3 High
CVSS3
5.1 Medium
CVSS2