Vulnerability CVE-2019-17011: Information
Description
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Fixed packages
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1591334 |
|
https://www.mozilla.org/security/advisories/mfsa2019-38/ |
|
https://www.mozilla.org/security/advisories/mfsa2019-37/ |
|
https://www.mozilla.org/security/advisories/mfsa2019-36/ |
|
openSUSE-SU-2020:0002 |
|
openSUSE-SU-2020:0003 |
|
USN-4241-1 |
|
RHSA-2020:0295 |
|
RHSA-2020:0292 |
|
GLSA-202003-02 |
|
GLSA-202003-10 |
|
USN-4335-1 |
|