Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17026

Опубликовано: 08 янв. 2020
Источник: redhat
CVSS3: 8.8

Описание

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 5thunderbirdOut of support scope
Red Hat Enterprise Linux 6firefoxFixedRHSA-2020:008613.01.2020
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2020:012316.01.2020
Red Hat Enterprise Linux 7firefoxFixedRHSA-2020:008513.01.2020
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2020:012016.01.2020
Red Hat Enterprise Linux 8firefoxFixedRHSA-2020:011114.01.2020
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2020:012716.01.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsthunderbirdFixedRHSA-2020:029230.01.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsfirefoxFixedRHSA-2020:029530.01.2020

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=1789214Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
nvd
почти 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
debian
почти 6 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting arra ...

CVSS3: 8.8
github
больше 3 лет назад

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

CVSS3: 8.8
fstec
около 6 лет назад

Уязвимость JIT-компилятора IonMonkey браузеров Firefox и Firefox ESR, связанная с доступом к ресурсу через несовместимые типы, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

8.8 High

CVSS3