Remote code execution in Firefox

A vulnerability CVE-2019-11707 has been discovered in the Firefox browser, according to some reports. which allows This allows an attacker to remotely execute arbitrary code using JavaScript. Mozilla states that the vulnerability is already being exploited by malicious actors.

The problem lies in the implementation of the Array.pop method. Details have not yet been disclosed..

The vulnerability has been patched in Firefox 67.0.3 and Firefox ESR 60.7.1. Therefore, it can be confidently stated that all versions of Firefox 60.x are vulnerable (it is quite possible that earlier versions are also affected; concerning Array.prototype.pop(), it has been implemented since the very first version of Firefox).

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster