5 ms·
We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demons
by dveditz_ 4y ago
We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory.
Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed only to Zero Day Initiative staff (the contest organizers) and Mozilla. They have not been discovered on any website in the wild.
- dredmorbius 4y agoWho are "we" here?
- AlexSW 4y agoJudging by the post and the user's post history, almost certainly 'we' refers to Mozilla.
- dredmorbius 4y agoPost history suggested at best ex- Mozilla to me.
- _rdvw 4y agoPerhaps Tails copy/pasted the page from an older notice? Although the two patches have now been public for ~6 days at this point.
- dveditz_ 4y agoTails has updated their advisory to remove that statement: https://tails.boum.org/security/prototype_pollution/index.en.html https://tails.boum.org/security/prototype_pollution/index.en...