Showing questions for topic:
Kukhonjiswa imibuzo ethegiwe:

CVE-2024-4367 in 115.19.0esr - still vulnerable?

Hi, During some tests I found that FF 115.19.0esr can still execute arbitrary JS similarly to CVE-2024-4367. I’ve checked the versions and > 115.11esr should be patch… (funda kabanzi)

Hi, During some tests I found that FF 115.19.0esr can still execute arbitrary JS similarly to CVE-2024-4367. I’ve checked the versions and > 115.11esr should be patched. Any payload with ‘/JS’ taken from https://github.com/luigigubello/PayloadsAllThePDFs/tree/main will do. Since this is probably important – FontMatrix is *not* working (no JS), original PoC (https://codeanlabs.com/wp-content/uploads/2024/05/poc_generalized_CVE-2024-4367.pdf) is also *not* working. I also wasn’t able to call an external script and so far haven’t found any path to exploit it beyond an alertbox. However, it still bothers me a lot and I’d like to know whether it’s the correct, expected behavior with FF+pdf.js, is it a vulnerability, or maybe my browser was somehow corrupted or is using some other mechanism that’s not within your control (my settings? about:config?).

Steps to re-create: 1. Open file in notepad 2. Add ‘/OpenAction 99 0 R’ after ‘lang’ in ‘1 0 obj section’ 3. After ‘endobj’ add ‘99 0 obj <</Type /Action /S /JavaScript /JS (app.alert\(1\);)>>’ 4. Result – alertbox popping twice

Kusonjululiwe Okugcinwe kunqolobane 3 973

Firefox

Hello Mozilla, I have a Lenovo G700 laptop with the WINDOWS 7 Pro operating system My browser is Firefox 115.19.0 (see file Firefox.jpg) During the security check in onli… (funda kabanzi)

Hello Mozilla, I have a Lenovo G700 laptop with the WINDOWS 7 Pro operating system My browser is Firefox 115.19.0 (see file Firefox.jpg) During the security check in online banking I am told that the browser is out of date (see firefox2.jpg) But I can only update the version and it says "Firefox is up to date" What's wrong with that?

Best regards Heimo Ganzoort

Okugcinwe kunqolobane 2 154