CVE-2019-11708: Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer.
Other sources
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.7.2 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 67.0.4 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.7.2
Event History
Frequently Asked Questions
What is CVE-2019-11708?
CVE-2019-11708 is a vulnerability in Mozilla Firefox and Thunderbird that allows a compromised child process to open web content chosen by the non-sandboxed parent process.
How severe is CVE-2019-11708?
CVE-2019-11708 has a severity rating of critical.
How does CVE-2019-11708 impact Mozilla Firefox?
CVE-2019-11708 affects Mozilla Firefox versions up to and including 67.0.4.
How does CVE-2019-11708 impact Mozilla Firefox ESR?
CVE-2019-11708 affects Mozilla Firefox ESR versions up to and including 60.7.2.
How does CVE-2019-11708 impact Mozilla Thunderbird?
CVE-2019-11708 affects Mozilla Thunderbird versions up to and including 60.7.2.
Are there any remedies available for CVE-2019-11708?
Yes, updating to Mozilla Firefox version 67.0.4 or Mozilla Firefox ESR version 60.7.2 will fix the vulnerability.
Where can I find more information about CVE-2019-11708?
You can find more information about CVE-2019-11708 at the following references: 1. [Bugzilla - Mozilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1559858) 2. [Mozilla Security Advisory - MFSA2019-19](https://www.mozilla.org/en-US/security/advisories/mfsa2019-19/) 3. [Mozilla Security Advisory - MFSA2019-20](https://www.mozilla.org/en-US/security/advisories/mfsa2019-20/)