摘要:
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.
安全等级: Low
公告ID: KylinSec-SA-2024-4149
发布日期: 2024年11月21日
关联CVE: CVE-2019-25136
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2019-25136 | KY3.4-5A | firefox | Unaffected |
CVE-2019-25136 | KY3.5.2 | firefox | Unaffected |
CVE-2019-25136 | V6 | firefox | Unaffected |