CVE-2019-11694: High severity thunderbird vulnerability
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at that memory location. Note: this issue only occurs on Windows. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Other sources
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at that memory location. Note: this issue only occurs on Windows. Other operating systems are unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-9821
- CVE-2019-11695
- CVE-2019-11696
- CVE-2019-11697
- CVE-2019-11700
- CVE-2019-11699
- CVE-2019-11701
- CVE-2019-9814
Frequently Asked Questions
What is CVE-2019-11694?
CVE-2019-11694 is a vulnerability that exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file, resulting in the potential leaking of information stored at that memory location.
Which software is affected by CVE-2019-11694?
CVE-2019-11694 affects Mozilla Firefox versions up to and excluding 67, Mozilla Firefox ESR versions up to and excluding 60.7, and Mozilla Thunderbird versions up to and excluding 60.7.
Is Microsoft Windows affected by CVE-2019-11694?
No, Microsoft Windows is not vulnerable to CVE-2019-11694.
What is the severity level of CVE-2019-11694?
CVE-2019-11694 has a severity level of 7.5 (high).
How can I fix CVE-2019-11694?
To fix CVE-2019-11694, update to the latest version of Mozilla Firefox, Mozilla Firefox ESR, or Mozilla Thunderbird.