CVE-2019-11696: Input Validation
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11696?
CVE-2019-11696 is a vulnerability where files with the .JNLP extension used for Java web start applications are not treated as executable content for download prompts, allowing users to mistakenly launch an executable binary locally.
Which software is affected by CVE-2019-11696?
Mozilla Firefox versions up to and excluding 67.0, as well as certain versions of the Firefox package in Ubuntu and Debian, are affected by CVE-2019-11696.
What is the severity of CVE-2019-11696?
CVE-2019-11696 has a severity rating of high (7.8).
How can I fix CVE-2019-11696 in Mozilla Firefox?
To fix CVE-2019-11696 in Mozilla Firefox, update your browser to version 67.0 or higher.
Where can I find more information about CVE-2019-11696?
You can find more information about CVE-2019-11696 on the Mozilla Bugzilla and Mozilla Security Advisories websites.