FirefoxÇå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-10Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17026£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Firefox 72.0.1ºÍFirefox ESR 68.4.1֮ǰ°æ±¾
Îó²î¸ÅÊö
Mozilla FirefoxºÍMozilla Firefox ESR¶¼ÊÇÃÀ¹úMozilla»ù½ð»áµÄ²úÆ·¡£¡£¡£¡£¡£Mozilla FirefoxÊÇÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£¡£¡£¡£¡£Mozilla Firefox ESRÊÇFirefox(Webä¯ÀÀÆ÷)µÄÒ»¸öÑÓÉìÖ§³Ö°æ±¾¡£¡£¡£¡£¡£
MozillaÐû²¼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÒÑÔÚÒ°Íâ±»Æð¾¢Ê¹ÓõÄÎó²î£¨CVE-2019-17026£©¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÃÓÚMozillaµÄJavaScriptÒýÇæSpiderMonkeyµÄJavaScriptʵʱ£¨JIT£©±àÒëÆ÷IonMonkeyÖеÄÒ»¸öÀàÐÍ»ìÏýÎó²î¡£¡£¡£¡£¡£Æ¾Ö¤MozillaµÄ½¨Ò飬£¬£¬£¬£¬£¬£¬JIT±àÒëÆ÷Öб£´æÈ±ÏÝ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¡°ÉèÖÃÊý×éÔªËØµÄÓÖÃûÐÅÏ¢²»×¼È·¡±£¬£¬£¬£¬£¬£¬£¬ÌØÊâÊÇÔÚStureEnthPopleºÍFaliLabSturEngEnterÖС£¡£¡£¡£¡£Ç±ÔÚ¹¥»÷Õß¿Éͨ¹ý½«Óû§Öض¨ÏòÖÁ¶ñÒâÍøÒ³À´´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼Ö´úÂëÖ´Ðлò´¥·¢Í߽⡣¡£¡£¡£¡£ÃÀ¹úCISAÒ²·¢³öÖÒÑԳƹ¥»÷Õß¿ÉÄÜʹÓôËÎó²îÀ´¿ØÖÆÊÜÓ°ÏìµÄϵͳ£¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÓû§Éó²éMozillaÇ徲ת´ïºÍÓ¦ÓÃÇå¾²¸üС£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
MozillaÒÑÐû²¼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1¡£¡£¡£¡£¡£ÓÉÓÚ´ËÎó²îÒÑÔÚÄ¿µÄ¹¥»÷Öб»Ê¹Ó㬣¬£¬£¬£¬£¬£¬½¨ÒéFirefoxÓû§¾¡¿ìÉý¼¶£ºhttps://www.mozilla.org/en-US/security/advisories/mfsa2020-03/¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/mozilla-firefox-7201-patches-actively-exploited-zero-day/


¾©¹«Íø°²±¸11010802024551ºÅ