Firefox°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17026 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Firefox 72.0.1ºÍFirefox ESR 68.4.1֮ǰ°æ±¾


·ì϶¸ÅÊö


Mozilla FirefoxºÍMozilla Firefox ESR¶¼ÊÇÃÀ¹úMozilla»ù½ð»áµÄ²úÆ·¡£Mozilla FirefoxÊÇÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£Mozilla Firefox ESRÊÇFirefox(Webä¯ÀÀÆ÷)µÄÒ»¸öµ¢¸éÖ§³Ö°æ±¾¡£


Mozilla°ä²¼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1 £¬½¨¸´ÒÑÔÚÒ°±í±»»ý¼«ÀûÓõķì϶£¨CVE-2019-17026£©¡£¸Ã·ì϶ÊÇÓÃÓÚMozillaµÄJavaScriptÒýÇæSpiderMonkeyµÄJavaScriptʵʱ£¨JIT£©±àÒëÆ÷IonMonkeyÖеÄÒ»¸öÀàÐÍ»ìºÏ·ì϶¡£Æ¾¾ÝMozillaµÄ½¨Òé £¬JIT±àÒëÆ÷ÖдæÔÚȱµã £¬ÓÉÓÚ¡°ÉèÖÃÊý×éÔªËØµÄ±ðºÅÐÅÏ¢²»ÕýÈ·¡± £¬³ö¸ñÊÇÔÚStureEnthPopleºÍFaliLabSturEngEnterÖС£Ç±ÔÚ¹¥»÷Õß¿Éͨ¹ý½«Óû§³Á¶¨ÏòÖÁ¶ñÒâÍøÒ³À´´¥·¢¸Ã·ì϶ £¬µ¼Ö´úÂëÖ´Ðлò´¥·¢±ÀÀ£¡£ÃÀ¹úCISAÒ²·¢³öÖÒ¸æ³Æ¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶À´½ÚÔìÊÜÓ°ÏìµÄϵͳ £¬²¢½¨ÒéÓû§²é¿´Mozilla°²È«´«µÝºÍÀûÓð²È«¸üС£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


MozillaÒѰ䲼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1¡£ÓÉÓÚ´Ë·ì϶ÒÑÔÚÖ¸±ê¹¥»÷Öб»ÀûÓà £¬½¨ÒéFirefoxÓû§¾¡¿ìÉý¼¶£ºhttps://www.mozilla.org/en-US/security/advisories/mfsa2020-03/¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/mozilla-firefox-7201-patches-actively-exploited-zero-day/