First published: Tue May 21 2019(Updated: )
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at that memory location. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <67 | 67 |
<67 | 67 | |
<60.7 | 60.7 | |
<60.7 | 60.7 | |
Mozilla Firefox | <67.0 | |
Mozilla Firefox ESR | <60.7.0 | |
Mozilla Thunderbird | <60.7.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-11694 is a vulnerability that exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file, resulting in the potential leaking of information stored at that memory location.
CVE-2019-11694 affects Mozilla Firefox versions up to and excluding 67, Mozilla Firefox ESR versions up to and excluding 60.7, and Mozilla Thunderbird versions up to and excluding 60.7.
No, Microsoft Windows is not vulnerable to CVE-2019-11694.
CVE-2019-11694 has a severity level of 7.5 (high).
To fix CVE-2019-11694, update to the latest version of Mozilla Firefox, Mozilla Firefox ESR, or Mozilla Thunderbird.