Firefox°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-01-10·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17026£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Firefox 72.0.1ºÍFirefox ESR 68.4.1֮ǰ°æ±¾
·ì϶¸ÅÊö
Mozilla FirefoxºÍMozilla Firefox ESR¶¼ÊÇÃÀ¹úMozilla»ù½ð»áµÄ²úÆ·¡£¡£¡£¡£¡£Mozilla FirefoxÊÇÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£¡£¡£¡£¡£Mozilla Firefox ESRÊÇFirefox(Webä¯ÀÀÆ÷)µÄÒ»¸öµ¢¸éÖ§³Ö°æ±¾¡£¡£¡£¡£¡£
Mozilla°ä²¼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1£¬£¬£¬£¬£¬£¬£¬½¨¸´ÒÑÔÚÒ°±í±»»ý¼«ÀûÓõķì϶£¨CVE-2019-17026£©¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÃÓÚMozillaµÄJavaScriptÒýÇæSpiderMonkeyµÄJavaScriptʵʱ£¨JIT£©±àÒëÆ÷IonMonkeyÖеÄÒ»¸öÀàÐÍ»ìºÏ·ì϶¡£¡£¡£¡£¡£Æ¾¾ÝMozillaµÄ½¨Ò飬£¬£¬£¬£¬£¬£¬JIT±àÒëÆ÷ÖдæÔÚȱµã£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¡°ÉèÖÃÊý×éÔªËØµÄ±ðºÅÐÅÏ¢²»ÕýÈ·¡±£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚStureEnthPopleºÍFaliLabSturEngEnterÖÓ×£¡£¡£¡£¡£Ç±ÔÚ¹¥»÷Õß¿Éͨ¹ý½«Óû§³Á¶¨ÏòÖÁ¶ñÒâÍøÒ³À´´¥·¢¸Ã·ì϶£¬£¬£¬£¬£¬£¬£¬µ¼Ö´úÂëÖ´Ðлò´¥·¢±ÀÀ£¡£¡£¡£¡£¡£ÃÀ¹úCISAÒ²·¢³öÖÒ¸æ³Æ¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶À´½ÚÔìÊÜÓ°ÏìµÄϵͳ£¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÓû§²é¿´Mozilla°²È«´«µÝºÍÀûÓð²È«¸üС£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
½¨¸´½¨Òé
MozillaÒѰ䲼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1¡£¡£¡£¡£¡£ÓÉÓÚ´Ë·ì϶ÒÑÔÚÖ¸±ê¹¥»÷Öб»ÀûÓ㬣¬£¬£¬£¬£¬£¬½¨ÒéFirefoxÓû§¾¡¿ìÉý¼¶£ºhttps://www.mozilla.org/en-US/security/advisories/mfsa2020-03/¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/mozilla-firefox-7201-patches-actively-exploited-zero-day/


¾©¹«Íø°²±¸11010802024551ºÅ