Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mozilla pdfjs-dist安全漏洞(CVE-2024-4367) #239

Open
foyaga opened this issue May 21, 2024 · 0 comments
Open

Mozilla pdfjs-dist安全漏洞(CVE-2024-4367) #239

foyaga opened this issue May 21, 2024 · 0 comments
Labels
watchvuln watchvuln推送

Comments

@foyaga
Copy link
Owner

foyaga commented May 21, 2024

漏洞描述:

###影响
如果使用pdf.js加载恶意PDF,并且PDF.js配置为'isEvalSupported'设置为'true'(这是默认值),则不受限制的攻击者控制的JavaScript将在托管域的上下文中执行。

###补丁
该补丁删除了“eval”的使用:
mozilla/pdf.js#18015

###变通办法
将选项'isEvalSupported'设置为'false'。

##参考
https://bugzilla.mozilla.org/show\_bug.cgi?id\=1893645

参考链接:

@foyaga foyaga added the watchvuln watchvuln推送 label May 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
watchvuln watchvuln推送
Projects
None yet
Development

No branches or pull requests

1 participant