公告ID: KYLIN-2019-11717
安全等级: 中等
产品: Kylin V3
发布日期: 2019年7月10日
CVE: CVE-2019-11717
CVSS3评分: 6.1
概述:
None 描述:
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. 系统版本:
KYLIN 3.0.x
KYLIN 3.2.x
KYLIN 3.2.x
KYLIN 3.3.x
KYLIN 3.3.x
KYLIN 3.4.x
KYLIN 3.4.x
受影响包列表:
firefox
firefox-60.8.0-1.el6_10
thunderbird-60.8.0-1.el6_10
firefox-60.8.0-1.el7_6
thunderbird-60.8.0-1.el7_6
firefox-60.8.0-1.el8_0
thunderbird-60.8.0-1.el8_0