• CVE-2023-29532

发布时间: 2024年6月14日

修改时间: 2024年6月21日

概要

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS v3 指标

NVD openEuler
CVSS评分 5.5 5.5
Attack Vector Local Network
Attack Complexity Low Low
Privileges Required Low None
User Interaction None Required
Scope Unchanged Unchanged
Confidentiality None None
Integrity High High
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-2728 A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10. 2024年6月14日
KylinSec-SA-2024-2940 mozjs78 security update 2024年6月21日
KylinSec-SA-2024-3648 mozjs78 security update 2024年6月21日

影响产品

产品 状态
KY3.4-5A mozjs78 Fixed
KY3.5.2 mozjs78 Fixed
V6 mozjs78 Unaffected