Firefox |UAFÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-050x00 Îó²î¸ÅÊö
²úÆ·Ãû³Æ |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
Firefox |
CVE-2020-6819 |
ÄÚ´æÆÆËð |
¸ßΣ |
ÊÇ |
Firefox < 74.0.1 Firefox ESR < 68.6.1 |
Firefox |
CVE-2020-6820 |
ÄÚ´æÆÆËð |
¸ßΣ |
ÊÇ |
Firefox < 74.0.1 Firefox ESR < 68.6.1 |
0x01 Îó²îÏêÇé
Mozilla FirefoxÊÇÃÀ¹úMozilla»ù½ð»áµÄÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£¡£¡£¡£¡£
2020Äê4ÔÂ3ÈÕ£¬£¬£¬£¬£¬MozillaÔÚÆäÇ徲ͨ¸æÖÐÅú¶ÆäÐÞ¸´ÁËÁ½¸öÕë¶ÔFirefoxä¯ÀÀÆ÷µÄ0dayÎó²î£¨CVE-2020-6819¡¢CVE-2020-6820£©¡£¡£¡£¡£¡£
CVE-2020-6819ÊÇä¯ÀÀÆ÷ÔÚ´¦Öóͷ£nsDocShellÎö¹¹º¯Êýʱ£¬£¬£¬£¬£¬¾ºÕùÌõ¼þ¿ÉÄܻᵼÖÂuse-after-free£¨ÊÍ·ÅÖØÓã©Ê¹¶ñÒâ¹¥»÷Õß½«´úÂë·ÅÈëFirefoxÄÚ´æÖУ¬£¬£¬£¬£¬²¢ÔÚä¯ÀÀÆ÷µÄÉÏÏÂÎÄÖÐÖ´ÐиôúÂë¡£¡£¡£¡£¡£
CVE-2020-6820ÊÇä¯ÀÀÆ÷ÔÚ´¦Öóͷ£ReadableStreamʱ£¬£¬£¬£¬£¬¾ºÕùÌõ¼þ¿ÉÄܻᵼÖÂuse-after-free£¨ÊÍ·ÅÖØÓã©Ê¹¶ñÒâ¹¥»÷Õß½«´úÂë·ÅÈëFirefoxÄÚ´æÖУ¬£¬£¬£¬£¬²¢ÔÚä¯ÀÀÆ÷µÄÉÏÏÂÎÄÖÐÖ´ÐиôúÂë¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÈí¼þ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶ä¯ÀÀÆ÷ÖÁFirefox 74.0.1 »òFirefox ESR 68.6.1°æ±¾¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://zh-cn.tenable.com/blog/cve-2020-6819-cve-2020-6820-critical-mozilla-firefox-zero-day-vulnerabilities-exploited-in-wild?tns_redirect=true
0x04 ²Î¿¼Á´½Ó
https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/