Описание
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | ||
| Red Hat Enterprise Linux 6 | firefox | Fixed | RHSA-2019:1765 | 11.07.2019 |
| Red Hat Enterprise Linux 6 | thunderbird | Fixed | RHSA-2019:1777 | 15.07.2019 |
| Red Hat Enterprise Linux 7 | firefox | Fixed | RHSA-2019:1763 | 11.07.2019 |
| Red Hat Enterprise Linux 7 | thunderbird | Fixed | RHSA-2019:1775 | 15.07.2019 |
| Red Hat Enterprise Linux 8 | firefox | Fixed | RHSA-2019:1764 | 11.07.2019 |
| Red Hat Enterprise Linux 8 | thunderbird | Fixed | RHSA-2019:1799 | 16.07.2019 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbo ...
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Уязвимость браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, связанная с недостатками разграничения доступа, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3