First published: Tue Jun 18 2019(Updated: )
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <60.7.2 | 60.7.2 |
Mozilla Firefox | <67.0.3 | 67.0.3 |
Mozilla Firefox ESR | <60.7.1 | 60.7.1 |
Mozilla Firefox | <60.7.3 | |
Mozilla Firefox ESR | <60.7.1 | |
Mozilla Thunderbird | <60.7.2 | |
Mozilla Firefox and Thunderbird | ||
<60.7.3 | ||
<60.7.1 | ||
<60.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11707 is a type confusion vulnerability in Mozilla Firefox and Thunderbird that allows for an exploitable crash.
CVE-2019-11707 affects Firefox ESR versions prior to 60.7.1, Firefox versions prior to 67.0.3, and Thunderbird versions prior to 60.7.2.
CVE-2019-11707 has a severity rating of 8.8 (Critical).
To fix CVE-2019-11707, update your Firefox ESR version to 60.7.1 or later, update your Firefox version to 67.0.3 or later, and update your Thunderbird version to 60.7.2 or later.
You can find more information about CVE-2019-11707 on the Mozilla website at https://www.mozilla.org/en-US/security/advisories/mfsa2019-20/ and https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/ as well as on the Bugzilla page at https://bugzilla.mozilla.org/show_bug.cgi?id=1544386.