Firefox |°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-14

0x00 ·ì϶¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Firefox

CVE-2020-6821

ÐÅϢй¶

¸ßΣ

ÊÇ

Firefox < 75

Firefox

CVE-2020-6822

»º³åÇøÒç³ö

ÖÐΣ

ÊÇ

Firefox < 75

Firefox ESR < 68.7

Firefox

CVE-2020-6823

ÐÅϢй¶

ÖÐΣ

ÊÇ

Firefox < 74

Firefox

CVE-2020-6824

ԽȨ½Ó¼û

ÖÐΣ

ÊÇ

Firefox < 75

Firefox

CVE-2020-6825

ÄÚ´æ·ÛËé

¸ßΣ

ÊÇ

Firefox ESR 68.6

Firefox 74

Firefox

CVE-2020-6826

ÄÚ´æ·ÛËé

¸ßΣ

ÊÇ

Firefox 74


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Mozilla FirefoxÊÇÃÀ¹úMozilla»ù½ð»áµÄÒ»¿î¿ªÔ´Webä¯ÀÀÆ÷¡£

2020Äê4ÔÂ7ÈÕ£¬MozillaÔÚÆä°²È«¹«¸æÖÐÅú¶Æä½¨¸´ÁËÁù¸ö·ì϶£¬¾ßÌåÈçÏ£º

CVE-2020-6821Êǵ±Ê¹ÓÃWebGLµÄcopyTexSubImage²½Öè´ÓÔ´×ÊÔ´ÖжÁÈ¡Êý¾Ýʱ£¬¹æ·¶ÒªÇó·µ»ØÖµÎªÁã¡£µ«´ËÄÚ´æÎ´³õʼ»¯£¬µ¼ÖÂDZÔÚµÄÃô¸ÐÊý¾Ýй¶¡£

CVE-2020-6822ÊÇÔÚGMPDecodeDataÖд¦ÖôóÓÚ4 GBµÄͼÏñʱ£¬¿ÉÄÜ»á²úÉúÔ½½çдÈë¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£

CVE-2020-6823ÊǶñÒâÀ©´ó·¨Ê½Í¨¹ýŲÓÃbrowser.identity.launchWebAuthFlowÀ´½ÚÔìredirect_uri£¬²¢»ñµÃAuth´úÂ룬ÔÚ·þÎñÌṩÉÌ´¦½Ó¼ûÓû§µÄÕÊ»§¡£

CVE-2020-6824ÊÇÔÚÁ½´Î´ò¿ª¸öÈËä¯ÀÀ´°¿Úʱ£¬·¨Ê½ÌìÉúÒ»ÑùµÄÃÜÂ루ǰÌ᣺FirefoxÒ»Ïò´¦ÓÚ´ò¿ª×´Ì¬£©¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄÍøÕ¾ÀûÓø÷ì϶»ñȡϵͳδÊÚȨµÄ½Ó¼ûȨÏÞ¡£

CVE-2020-6825ÊÇÔÚMozilla Firefox ESR 68.6°æ±¾ºÍFirefox 74°æ±¾ÖдæÔÚÄڴ氲ȫÐÔÃýÎó¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶°Ü»µÄÚ´æ»ò¿ÉÄÜÖ´ÐÐËÁÒâ´úÂë¡£

CVE-2020-6826ÊÇÔÚFirefox 74°æ±¾ÖдæÔÚÄڴ氲ȫÐÔÃýÎó¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶·ÛËéÄÚ´æ²¢Ö´ÐÐËÁÒâ´úÂë¡£


0x02 ´ëÖý¨Òé


³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º

https://www.mozilla.org/en-US/security/advisories/mfsa2020-12/


0x03 ÓйØÐÂÎÅ

https://www.auscert.org.au/bulletins/ESB-2020.1228/


0x04 ²Î¿¼Á´½Ó

https://www.mozilla.org/en-US/security/advisories/mfsa2020-12/


0x05 ¹¦·òÏß

2020-04-07 Firefox¹Ù·½°ä²¼·ì϶

2020-04-10 CVE°ä²¼¸Ã·ì϶


                                            GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾