Описание
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 74.0.1+build1-0ubuntu0.18.04.1 |
| devel | released | 75.0+build3-0ubuntu1 |
| eoan | released | 74.0.1+build1-0ubuntu0.19.10.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | released | 75.0+build3-0ubuntu1 |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | |
| upstream | released | 74.0.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1:68.7.0+build1-0ubuntu0.18.04.1 |
| devel | released | 1:68.7.0+build1-0ubuntu1 |
| eoan | released | 1:68.7.0+build1-0ubuntu0.19.10.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | released | 1:68.7.0+build1-0ubuntu1 |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | |
| upstream | released | 68.7.0 |
Показывать по
Ссылки на источники
EPSS
6.8 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Under certain conditions, when handling a ReadableStream, a race condi ...
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Уязвимость компонента ReadableStream веб-браузеров Firefox ESR и Firefox и почтового клиента Thunderbird, связанная с повторном освобождении области памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
EPSS
6.8 Medium
CVSS2
8.1 High
CVSS3