First published: Tue Jul 09 2019(Updated: )
A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <68 | 68 |
<68 | 68 | |
<60.8 | 60.8 | |
<60.8 | 60.8 | |
Mozilla Firefox | <68.0 | |
Mozilla Firefox ESR | <60.8.0 | |
Mozilla Thunderbird | <60.8.0 | |
<68 | 68 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2019-11713 is a use-after-free vulnerability in HTTP/2 that can result in a potentially exploitable crash.
CVE-2019-11713 affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
CVE-2019-11713 has a severity rating of 9.8 (Critical).
To fix CVE-2019-11713, you should update Firefox ESR to version 60.8 or later, update Firefox to version 68 or later, and update Thunderbird to version 60.8 or later.
You can find more information about CVE-2019-11713 on the Mozilla Bugzilla and Mozilla Security Advisories websites.