Firefox |°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-140x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Firefox |
CVE-2020-6821 |
ÐÅϢй¶ |
¸ßΣ |
ÊÇ |
Firefox < 75 |
|
Firefox |
CVE-2020-6822 |
»º³åÇøÒç³ö |
ÖÐΣ |
ÊÇ |
Firefox < 75 Firefox ESR < 68.7 |
|
Firefox |
CVE-2020-6823 |
ÐÅϢй¶ |
ÖÐΣ |
ÊÇ |
Firefox < 74 |
|
Firefox |
CVE-2020-6824 |
ԽȨ½Ó¼û |
ÖÐΣ |
ÊÇ |
Firefox < 75 |
|
Firefox |
CVE-2020-6825 |
ÄÚ´æ·ÛËé |
¸ßΣ |
ÊÇ |
Firefox ESR 68.6 Firefox 74 |
|
Firefox |
CVE-2020-6826 |
ÄÚ´æ·ÛËé |
¸ßΣ |
ÊÇ |
Firefox 74 |
0x01 ·ì϶ÏêÇé
Mozilla FirefoxÊÇÃÀ¹úMozilla»ù½ð»áµÄÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£
2020Äê4ÔÂ7ÈÕ£¬MozillaÔÚÆä°²È«¹«¸æÖÐÅú¶Æä½¨¸´ÁËÁù¸ö·ì϶£¬¾ßÌåÈçÏ£º
CVE-2020-6821Êǵ±Ê¹ÓÃWebGLµÄcopyTexSubImage²½Öè´ÓÔ´×ÊÔ´ÖжÁÈ¡Êý¾Ýʱ£¬¹æ·¶ÒªÇó·µ»ØÖµÎªÁã¡£µ«´ËÄÚ´æÎ´³õʼ»¯£¬µ¼ÖÂDZÔÚµÄÃô¸ÐÊý¾Ýй¶¡£
CVE-2020-6822ÊÇÔÚGMPDecodeDataÖд¦ÖôóÓÚ4 GBµÄͼÏñʱ£¬¿ÉÄÜ»á²úÉúÔ½½çдÈë¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
CVE-2020-6823ÊǶñÒâÀ©´ó·¨Ê½Í¨¹ýŲÓÃbrowser.identity.launchWebAuthFlowÀ´½ÚÔìredirect_uri£¬²¢»ñµÃAuth´úÂ룬ÔÚ·þÎñÌṩÉÌ´¦½Ó¼ûÓû§µÄÕÊ»§¡£
CVE-2020-6824ÊÇÔÚÁ½´Î´ò¿ª¸öÈËä¯ÀÀ´°¿Úʱ£¬·¨Ê½ÌìÉúÒ»ÑùµÄÃÜÂ루ǰÌ᣺FirefoxÒ»Ïò´¦ÓÚ´ò¿ª×´Ì¬£©¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÍøÕ¾ÀûÓø÷ì϶»ñȡϵͳδÊÚȨµÄ½Ó¼ûȨÏÞ¡£
CVE-2020-6825ÊÇÔÚMozilla Firefox ESR 68.6°æ±¾ºÍFirefox 74°æ±¾ÖдæÔÚÄڴ氲ȫÐÔÃýÎó¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶°Ü»µÄÚ´æ»ò¿ÉÄÜÖ´ÐÐËÁÒâ´úÂë¡£
CVE-2020-6826ÊÇÔÚFirefox 74°æ±¾ÖдæÔÚÄڴ氲ȫÐÔÃýÎó¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶·ÛËéÄÚ´æ²¢Ö´ÐÐËÁÒâ´úÂë¡£
0x02 ´ëÖý¨Òé
³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º
https://www.mozilla.org/en-US/security/advisories/mfsa2020-12/
0x03 ÓйØÐÂÎÅ
https://www.auscert.org.au/bulletins/ESB-2020.1228/
0x04 ²Î¿¼Á´½Ó
https://www.mozilla.org/en-US/security/advisories/mfsa2020-12/
0x05 ¹¦·òÏß
2020-04-07 Firefox¹Ù·½°ä²¼·ì϶
2020-04-10 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ