摘要:
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.
安全等级: Low
公告ID: KylinSec-SA-2024-4412
发布日期: 2024年11月21日
关联CVE: CVE-2019-25136
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2019-25136 | KY3.4-5A | mozjs78 | Unaffected |
CVE-2019-25136 | KY3.5.2 | mozjs78 | Unaffected |
CVE-2019-25136 | V6 | mozjs78 | Unaffected |