CVE-2019-11707: Mozilla Firefox and Thunderbird Type Confusion Vulnerability
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
Other sources
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.7.2 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 67.0.3 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.7.1
Event History
Frequently Asked Questions
What is CVE-2019-11707?
CVE-2019-11707 is a type confusion vulnerability in Mozilla Firefox and Thunderbird that allows for an exploitable crash.
Which software versions are affected by CVE-2019-11707?
CVE-2019-11707 affects Firefox ESR versions prior to 60.7.1, Firefox versions prior to 67.0.3, and Thunderbird versions prior to 60.7.2.
What is the severity of CVE-2019-11707?
CVE-2019-11707 has a severity rating of 8.8 (Critical).
How can I fix CVE-2019-11707?
To fix CVE-2019-11707, update your Firefox ESR version to 60.7.1 or later, update your Firefox version to 67.0.3 or later, and update your Thunderbird version to 60.7.2 or later.
Where can I find more information about CVE-2019-11707?
You can find more information about CVE-2019-11707 on the Mozilla website at https://www.mozilla.org/en-US/security/advisories/mfsa2019-20/ and https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/ as well as on the Bugzilla page at https://bugzilla.mozilla.org/show_bug.cgi?id=1544386.