Mozilla brengt binnen 24 uur update uit voor Pwn2Own-kwetsbaarheden

0
352
Mozilla patcht twee zero-day kwetsbaarheden in Firefox

Security vulnerabilities fixed in Firefox 66.0.1

Announced
March 22, 2019
Impact
critical
Products
Firefox
Fixed in

#CVE-2019-9810: IonMonkey MArraySlice has incorrect alias information

Reporter
Richard Zhu and Amat Cama via Trend Micro’s Zero Day Initiative
Impact
critical
Description

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow.

References

#CVE-2019-9813: Ionmonkey type confusion with __proto__ mutations

Reporter
Niklas Baumstark via Trend Micro’s Zero Day Initiative
Impact
critical
Description

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write.

References

Source link

Vorig artikelEditor Notepad++ voortaan geleverd met GPG-handtekening
Volgend artikelNieuwe update Google Chrome voor 60 kwetsbaarheden beschikbaar