Firefox°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17026£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Firefox 72.0.1ºÍFirefox ESR 68.4.1֮ǰ°æ±¾


·ì϶¸ÅÊö


Mozilla FirefoxºÍMozilla Firefox ESR¶¼ÊÇÃÀ¹úMozilla»ù½ð»áµÄ²úÆ·¡£Mozilla FirefoxÊÇÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£Mozilla Firefox ESRÊÇFirefox(Webä¯ÀÀÆ÷)µÄÒ»¸öµ¢¸éÖ§³Ö°æ±¾¡£


Mozilla°ä²¼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1£¬½¨¸´ÒÑÔÚÒ°±í±»»ý¼«ÀûÓõķì϶£¨CVE-2019-17026£©¡£¸Ã·ì϶ÊÇÓÃÓÚMozillaµÄJavaScriptÒýÇæSpiderMonkeyµÄJavaScriptʵʱ£¨JIT£©±àÒëÆ÷IonMonkeyÖеÄÒ»¸öÀàÐÍ»ìºÏ·ì϶¡£Æ¾¾ÝMozillaµÄ½¨Ò飬JIT±àÒëÆ÷ÖдæÔÚȱµã£¬ÓÉÓÚ¡°ÉèÖÃÊý×éÔªËØµÄ±ðºÅÐÅÏ¢²»ÕýÈ·¡±£¬³ö¸ñÊÇÔÚStureEnthPopleºÍFaliLabSturEngEnterÖС£Ç±ÔÚ¹¥»÷Õß¿Éͨ¹ý½«Óû§³Á¶¨ÏòÖÁ¶ñÒâÍøÒ³À´´¥·¢¸Ã·ì϶£¬µ¼Ö´úÂëÖ´Ðлò´¥·¢±ÀÀ£¡£ÃÀ¹úCISAÒ²·¢³öÖÒ¸æ³Æ¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶À´½ÚÔìÊÜÓ°ÏìµÄϵͳ£¬²¢½¨ÒéÓû§²é¿´Mozilla°²È«´«µÝºÍÀûÓð²È«¸üС£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


MozillaÒѰ䲼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1¡£ÓÉÓÚ´Ë·ì϶ÒÑÔÚÖ¸±ê¹¥»÷Öб»ÀûÓ㬽¨ÒéFirefoxÓû§¾¡¿ìÉý¼¶£ºhttps://www.mozilla.org/en-US/security/advisories/mfsa2020-03/¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/mozilla-firefox-7201-patches-actively-exploited-zero-day/