Mozilla發布Firefox更新,修補已遭利用的零時差漏洞
支付動態 · 2024-10-11

近日Mozilla發布Firefox及Firefox ESR更新,目的是修補重大層級的CVE-2024-9680,該基金會指出,他們已掌握實際利用這項漏洞的活動情資

10月9日Mozilla基金會發布資安公告,緊急修補Firefox重大層級的零時差漏洞CVE-2024-9680,這項漏洞由資安業者ESET通報,存在於Animation元件的時間軸,為記憶體釋放後再存取使用(Use After Free)漏洞,CVSS風險評分達到9.8(滿分10分),該基金會發布Firefox 131.0.2,以及長期支援版(ESR)128.3.1、115.16.1修補。值得留意的是,已有攻擊者試圖利用這項漏洞。

針對這項漏洞帶來的影響,Mozilla基金會指出,攻擊者若是觸發漏洞,就有機會藉由Animation元件的時間軸,引發記憶體釋放後再存取使用的現象,而能在特定處理程序執行程式碼。

他們特別提及,已接獲漏洞被實際利用的通報。究竟駭客如何利用漏洞?該基金會並未進一步說明。

想要修補上述漏洞並不難,因為Firefox會自行下載新版程式,並在功能選單提醒軟體更新,用戶應依照指示套用並重新啟動瀏覽器,即可緩解這項漏洞。

Popular articles
New Jersey July Gambling Revenue Hits $606M, Sweeps Casinos Banned
Regulation
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
That’s a Wrap: AffPapa Conference Madrid 2026 Highlights
Online Game
Manila delivers: Highlights from SiGMA Asia 2026 
Southeast Asia
GAT Expo CDMX 2026 Kicks Off Today in Mexico with a Sold-Out Opening Reception at Big Bola Casino Santa Fe
Marketing
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
Global Game Connect (GGC) 2027 Officially Opens Sponsorship & Exhibition Opportunities in Sri Lanka!
HUIDU Focus
British gambling levy rates confirmed for each vertical
Regulation
PropellerAds Positions Itself as a Go-To Traffic Source for iGaming Advertisers Ahead of a High-Demand Season
Marketing
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Indiana online casino bill stalls in House committee
Regulation
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Home
Game
Cooperation
Find
My