Firefox |UAF·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-050x00 ·ì϶¸ÅÊö
|
²úÆ·Ãû³Æ |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Firefox |
CVE-2020-6819 |
ÄÚ´æ·ÛËé |
¸ßΣ |
ÊÇ |
Firefox < 74.0.1 Firefox ESR < 68.6.1 |
|
Firefox |
CVE-2020-6820 |
ÄÚ´æ·ÛËé |
¸ßΣ |
ÊÇ |
Firefox < 74.0.1 Firefox ESR < 68.6.1 |
0x01 ·ì϶ÏêÇé
Mozilla FirefoxÊÇÃÀ¹úMozilla»ù½ð»áµÄÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£
2020Äê4ÔÂ3ÈÕ£¬MozillaÔÚÆä°²È«¹«¸æÖÐÅú¶Æä½¨¸´ÁËÁ½¸öÕë¶ÔFirefoxä¯ÀÀÆ÷µÄ0day·ì϶£¨CVE-2020-6819¡¢CVE-2020-6820£©¡£
CVE-2020-6819ÊÇä¯ÀÀÆ÷ÔÚ´¦ÖÃnsDocShellÎö¹¹º¯Êýʱ£¬¾ºÕùǰÌá¿ÉÄܻᵼÖÂuse-after-free£¨¿ªÊͳÁÓã©Ê¹¶ñÒâ¹¥»÷Õß½«´úÂë·ÅÈëFirefoxÄÚ´æÖУ¬²¢ÔÚä¯ÀÀÆ÷µÄ¸ßµÍÎÄÖÐÖ´ÐиôúÂë¡£
CVE-2020-6820ÊÇä¯ÀÀÆ÷ÔÚ´¦ÖÃReadableStreamʱ£¬¾ºÕùǰÌá¿ÉÄܻᵼÖÂuse-after-free£¨¿ªÊͳÁÓã©Ê¹¶ñÒâ¹¥»÷Õß½«´úÂë·ÅÈëFirefoxÄÚ´æÖУ¬²¢ÔÚä¯ÀÀÆ÷µÄ¸ßµÍÎÄÖÐÖ´ÐиôúÂë¡£
0x02 ´ëÖý¨Òé
ĿǰÈí¼þ³§ÉÌÒѽ¨¸´¸Ã·ì϶£¬½¨ÒéÓû§Éý¼¶ä¯ÀÀÆ÷ÖÁFirefox 74.0.1 »òFirefox ESR 68.6.1°æ±¾¡£
0x03 ÓйØÐÂÎÅ
https://zh-cn.tenable.com/blog/cve-2020-6819-cve-2020-6820-critical-mozilla-firefox-zero-day-vulnerabilities-exploited-in-wild?tns_redirect=true
0x04 ²Î¿¼Á´½Ó
https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/


¾©¹«Íø°²±¸11010802024551ºÅ