{"id":20585,"date":"2022-03-07T03:44:59","date_gmt":"2022-03-07T05:44:59","guid":{"rendered":"https:\/\/teknomers.com\/fr\/2-nouveaux-bugs-mozilla-firefox-0-day-sous-attaque-active-corrigez-votre-navigateur-des-que-possible\/"},"modified":"2022-03-07T03:45:12","modified_gmt":"2022-03-07T05:45:12","slug":"2-nouveaux-bugs-mozilla-firefox-0-day-sous-attaque-active-corrigez-votre-navigateur-des-que-possible","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/2-nouveaux-bugs-mozilla-firefox-0-day-sous-attaque-active-corrigez-votre-navigateur-des-que-possible\/","title":{"rendered":"2 nouveaux bugs Mozilla Firefox 0-Day sous attaque active &#8211; Corrigez votre navigateur d\u00e8s que possible !"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Mozilla a pouss\u00e9 hors bande <a rel=\"nofollow noopener\" href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-09\/\" target=\"_blank\">mises \u00e0 jour de logiciel<\/a> \u00e0 son navigateur Web Firefox pour contenir deux vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 \u00e0 fort impact, qui, selon lui, sont activement exploit\u00e9es dans la nature.<\/p>\n<p>Suivis comme CVE-2022-26485 et CVE-2022-26486, les failles zero-day ont \u00e9t\u00e9 d\u00e9crites comme <a rel=\"nofollow noopener\" href=\"https:\/\/cwe.mitre.org\/data\/definitions\/416.html\" target=\"_blank\">probl\u00e8mes d&#8217;utilisation apr\u00e8s lib\u00e9ration<\/a> ayant un impact sur les transformations du langage de feuille de style extensible (<a rel=\"nofollow noopener\" href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/XSLT\" target=\"_blank\">XSLT<\/a>) le traitement des param\u00e8tres et la communication inter-processus WebGPU (<a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Inter-process_communication\" target=\"_blank\">CIB<\/a>) Cadre.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Nouveau-Wiper-Malware-ciblant-lUkraine-dans-le-cadre-de-loperation.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>XSLT est un langage bas\u00e9 sur XML utilis\u00e9 pour la conversion de documents XML en pages Web ou en documents PDF, tandis que WebGPU est une norme Web \u00e9mergente qui a \u00e9t\u00e9 pr\u00e9sent\u00e9e comme le successeur de la biblioth\u00e8que graphique JavaScript WebGL actuelle.<\/p>\n<p>La description des deux d\u00e9fauts est ci-dessous &#8211;<\/p>\n<ul>\n<li><strong>CVE-2022-26485<\/strong> \u2013 La suppression d&#8217;un param\u00e8tre XSLT pendant le traitement pourrait conduire \u00e0 une utilisation apr\u00e8s lib\u00e9ration exploitable<\/li>\n<li><strong>CVE-2022-26486<\/strong> &#8211; Un message inattendu dans le framework WebGPU IPC pourrait conduire \u00e0 un \u00e9chappement sandbox use-after-free et exploitable<\/li>\n<\/ul>\n<p>Les bogues d&#8217;utilisation apr\u00e8s lib\u00e9ration &#8211; qui pourraient \u00eatre exploit\u00e9s pour corrompre des donn\u00e9es valides et ex\u00e9cuter du code arbitraire sur des syst\u00e8mes compromis &#8211; proviennent principalement d&#8217;une &#8220;confusion sur la partie du programme responsable de la lib\u00e9ration de la m\u00e9moire&#8221;.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646326908_645_Correctifs-critiques-publies-pour-la-gamme-Cisco-Expressway-les-produits.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Mozilla a reconnu que &#8220;nous avons eu des rapports d&#8217;attaques dans la nature&#8221; militarisant les deux vuln\u00e9rabilit\u00e9s mais n&#8217;a partag\u00e9 aucune sp\u00e9cificit\u00e9 technique li\u00e9e aux intrusions ou \u00e0 l&#8217;identit\u00e9 des acteurs malveillants les exploitant.<\/p>\n<p>Les chercheurs en s\u00e9curit\u00e9 Wang Gang, Liu Jialei, Du Sihang, Huang Yi et Yang Kang de Qihoo 360 ATA ont \u00e9t\u00e9 cr\u00e9dit\u00e9s d&#8217;avoir d\u00e9couvert et signal\u00e9 les lacunes.<\/p>\n<p>\u00c0 la lumi\u00e8re de l&#8217;exploitation active des failles, il est recommand\u00e9 aux utilisateurs de mettre \u00e0 niveau d\u00e8s que possible vers Firefox 97.0.2, Firefox ESR 91.6.1, Firefox pour Android 97.3.0, Focus 97.3.0 et Thunderbird 91.6.2.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/2-new-mozilla-firefox-0-day-bugs-under.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mozilla a pouss\u00e9 hors bande mises \u00e0 jour de logiciel \u00e0 son navigateur Web Firefox pour contenir deux vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 \u00e0 fort impact, qui, selon lui, sont activement exploit\u00e9es dans la nature. Suivis comme CVE-2022-26485 et CVE-2022-26486, les failles zero-day ont \u00e9t\u00e9 d\u00e9crites comme probl\u00e8mes d&#8217;utilisation apr\u00e8s lib\u00e9ration ayant un impact sur les transformations [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20586,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[19980,9261,1933,13953,4168,19981,4158,4165,4161,133,19979,4157,4159,4171,4170,4167,4160,19978,1281,4588,4163,4162,4172,4169,367,4166,877,4164],"class_list":["post-20585","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-0day","tag-active","tag-attaque","tag-bugs","tag-comment-pirater","tag-corrigez","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-firefox","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-mozilla","tag-navigateur","tag-nouveaux","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-securite-informatique","tag-securite-internet","tag-sous","tag-violation-de-donnees","tag-votre","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/20585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=20585"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/20585\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/20586"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=20585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=20585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=20585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}