First published: Tue Jul 09 2019(Updated: )
Mozilla developers and community members Andreea Pavel, Christian Holler, Honza Bambas, Jason Kratzer, and Jeff Gilbert reported memory safety bugs fixed in Firefox 68, Firefox ESR 60.8, and Thunderbird 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <68 | 68 |
<68 | 68 | |
<60.8 | 60.8 | |
<60.8 | 60.8 | |
Mozilla Firefox | <68.0 | |
Mozilla Firefox ESR | <60.8.0 | |
Mozilla Thunderbird | <60.8.0 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
Suse Package Hub | ||
SUSE Linux Enterprise | =12.0 | |
Debian Debian Linux | =8.0 | |
<68 | 68 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2019-11709 is a vulnerability related to memory safety bugs present in Firefox 67, Firefox ESR 60.7, and Thunderbird 60.7.
The severity of CVE-2019-11709 is critical with a severity value of 9.
To fix CVE-2019-11709, update to Mozilla Firefox version 68 or Mozilla Firefox ESR version 60.8.
You can find more information about CVE-2019-11709 on the Mozilla bugzilla page and the Mozilla security advisories page.
The CWE ID for CVE-2019-11709 is 787.