Firefox |Çå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-140x00 Îó²î¸ÅÊö
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
Firefox |
CVE-2020-6821 |
ÐÅϢй¶ |
¸ßΣ |
ÊÇ |
Firefox < 75 |
Firefox |
CVE-2020-6822 |
»º³åÇøÒç³ö |
ÖÐΣ |
ÊÇ |
Firefox < 75 Firefox ESR < 68.7 |
Firefox |
CVE-2020-6823 |
ÐÅϢй¶ |
ÖÐΣ |
ÊÇ |
Firefox < 74 |
Firefox |
CVE-2020-6824 |
ԽȨ»á¼û |
ÖÐΣ |
ÊÇ |
Firefox < 75 |
Firefox |
CVE-2020-6825 |
ÄÚ´æÆÆËð |
¸ßΣ |
ÊÇ |
Firefox ESR 68.6 Firefox 74 |
Firefox |
CVE-2020-6826 |
ÄÚ´æÆÆËð |
¸ßΣ |
ÊÇ |
Firefox 74 |
0x01 Îó²îÏêÇé
Mozilla FirefoxÊÇÃÀ¹úMozilla»ù½ð»áµÄÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£
2020Äê4ÔÂ7ÈÕ£¬£¬£¬MozillaÔÚÆäÇ徲ͨ¸æÖÐÅú¶ÆäÐÞ¸´ÁËÁù¸öÎó²î£¬£¬£¬ÏêϸÈçÏ£º
CVE-2020-6821Êǵ±Ê¹ÓÃWebGLµÄcopyTexSubImageÒªÁì´ÓÔ´×ÊÔ´ÖжÁÈ¡Êý¾Ýʱ£¬£¬£¬¹æ·¶ÒªÇó·µ»ØÖµÎªÁã¡£¡£¡£¡£¡£¡£¡£µ«´ËÄÚ´æÎ´³õʼ»¯£¬£¬£¬µ¼ÖÂDZÔÚµÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6822ÊÇÔÚGMPDecodeDataÖд¦Öóͷ£´óÓÚ4 GBµÄͼÏñʱ£¬£¬£¬¿ÉÄܻᱬ·¢Ô½½çдÈë¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6823ÊǶñÒâÀ©Õ¹³ÌÐòͨ¹ýŲÓÃbrowser.identity.launchWebAuthFlowÀ´¿ØÖÆredirect_uri£¬£¬£¬²¢»ñµÃAuth´úÂ룬£¬£¬ÔÚЧÀÍÌṩÉÌ´¦»á¼ûÓû§µÄÕÊ»§¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6824ÊÇÔÚÁ½´Î·¿ªË½ÈËä¯ÀÀ´°¿Úʱ£¬£¬£¬³ÌÐòÌìÉúÏàͬµÄÃÜÂ루Ìõ¼þ£ºFirefoxÒ»Ö±´¦ÓÚ·¿ª×´Ì¬£©¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÍøÕ¾Ê¹ÓøÃÎó²î»ñȡϵͳδÊÚȨµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6825ÊÇÔÚMozilla Firefox ESR 68.6°æ±¾ºÍFirefox 74°æ±¾Öб£´æÄÚ´æÇå¾²ÐÔ¹ýʧ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îËð»µÄÚ´æ»ò¿ÉÄÜÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6826ÊÇÔÚFirefox 74°æ±¾Öб£´æÄÚ´æÇå¾²ÐÔ¹ýʧ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÆÆËðÄÚ´æ²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://www.mozilla.org/en-US/security/advisories/mfsa2020-12/
0x03 Ïà¹ØÐÂÎÅ
https://www.auscert.org.au/bulletins/ESB-2020.1228/
0x04 ²Î¿¼Á´½Ó
https://www.mozilla.org/en-US/security/advisories/mfsa2020-12/
0x05 ʱ¼äÏß
2020-04-07 Firefox¹Ù·½Ðû²¼Îó²î
2020-04-10 CVEÐû²¼¸ÃÎó²î
