4 ms·
These are just the pwn2own vulnerabilities. Nowhere did Mozilla ever say they were being exploited in the wild.
by rebelwebmaster 4y ago
These are just the pwn2own vulnerabilities. Nowhere did Mozilla ever say they were being exploited in the wild.
- deleted 4y ago[deleted]
- mmastrac 4y agoPerhaps they moved fast: "Mozilla is aware of websites exploiting this vulnerability already."
- rebelwebmaster 4y agoCitation needed. Also, they've specifically called that out in the advisory when they're aware of that being the case. See the last out-of-band security update they released for example: https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/ https://www.mozilla.org/en-US/security/advisories/mfsa2022-0...
- dveditz_ 4y agoWe are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.
- dredmorbius 4y agoWho are "we" here?
- AlexSW 4y agoJudging by the post and the user's post history, almost certainly 'we' refers to Mozilla.
- dredmorbius 4y agoPost history suggested at best ex- Mozilla to me.
- _rdvw 4y agoPerhaps Tails copy/pasted the page from an older notice? Although the two patches have now been public for ~6 days at this point.
- dveditz_ 4y agoTails has updated their advisory to remove that statement: https://tails.boum.org/security/prototype_pollution/index.en.html https://tails.boum.org/security/prototype_pollution/index.en...