发布时间: 2024年6月14日
修改时间: 2024年6月21日
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
NVD | openEuler | |
---|---|---|
CVSS评分 | 5.5 | 5.5 |
Attack Vector | Local | Network |
Attack Complexity | Low | Low |
Privileges Required | Low | None |
User Interaction | None | Required |
Scope | Unchanged | Unchanged |
Confidentiality | None | None |
Integrity | High | High |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-2728 | A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.*Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10. | 2024年6月14日 |
KylinSec-SA-2024-2940 | mozjs78 security update | 2024年6月21日 |
KylinSec-SA-2024-3648 | mozjs78 security update | 2024年6月21日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5A | mozjs78 | Fixed |
KY3.5.2 | mozjs78 | Fixed |
V6 | mozjs78 | Unaffected |