Opened 5 years ago

Closed 5 years ago

Last modified 5 years ago

#11852 closed enhancement (fixed)

firefox-66.0.1

Reported by: Douglas R. Reno Owned by: ken@…
Priority: highest Milestone: 9.0
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

New point version

Change History (4)

comment:1 by Douglas R. Reno, 5 years ago

Priority: normalhighest
Mozilla Foundation Security Advisory 2019-09
Security vulnerabilities fixed in Firefox 66.0.1

Announced
    March 22, 2019
Impact
    critical
Products
    Firefox
Fixed in

        Firefox 66.0.1

#CVE-2019-9810: IonMonkey MArraySlice has incorrect alias information

Reporter
    Richard Zhu and Amat Cama via Trend Micro's Zero Day Initiative
Impact
    critical

Description

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow.
References

    Bug 1537924

#CVE-2019-9813: Ionmonkey type confusion with __proto__ mutations

Reporter
    Niklas Baumstark via Trend Micro's Zero Day Initiative
Impact
    critical

Description

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write.
References

    Bug 1538006


Two urgent zero days reported. This is an emergency release to fix them.

Seems to affect previous versions of Firefox as well. I highly recommend updating to 66.0.1 if you're on 63.x+

comment:2 by ken@…, 5 years ago

Owner: changed from blfs-book to ken@…
Status: newassigned

If anyone has stuck with the 60 esr series, that also seems to be affected - 60.6.1esr was also released.

comment:3 by ken@…, 5 years ago

Resolution: fixed
Status: assignedclosed

comment:4 by Bruce Dubbs, 5 years ago

Milestone: 8.59.0

Milestone renamed

Note: See TracTickets for help on using tickets.