Описание
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 55.0.2+build1-0ubuntu4 |
| bionic | released | 55.0.2+build1-0ubuntu4 |
| cosmic | released | 55.0.2+build1-0ubuntu4 |
| devel | released | 55.0.2+build1-0ubuntu4 |
| disco | released | 55.0.2+build1-0ubuntu4 |
| eoan | released | 55.0.2+build1-0ubuntu4 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [55.0.1+build2-0ubuntu0.14.04.2]] |
| esm-infra/focal | DNE | |
| focal | released | 55.0.2+build1-0ubuntu4 |
| groovy | released | 55.0.2+build1-0ubuntu4 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | ignored | end of standard support, was needs-triage |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-apps/bionic | ignored | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE |
Показывать по
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3
Связанные уязвимости
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
On Linux systems, if the content process is compromised, the sandbox b ...
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
Уязвимость реализации процесса для запуска дочерних элементов в песочнице sandbox broker браузера Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации, нарушить ее целостность или вызвать отказ в обслуживании
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3