First published: Tue Jul 09 2019(Updated: )
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <68 | 68 |
Mozilla Thunderbird | <68 | 68 |
Mozilla Firefox | <68.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-11714 is a vulnerability in Necko that allows it to access a child on the wrong thread during UDP connections, potentially leading to a crash.
This vulnerability affects Mozilla Firefox versions up to and excluding 68 and Mozilla Thunderbird versions up to and excluding 68.
CVE-2019-11714 has a severity rating of 9.8 (Critical).
To fix CVE-2019-11714, update Mozilla Firefox or Mozilla Thunderbird to version 68 or newer.
You can find more information about CVE-2019-11714 on the Mozilla Bugzilla and Mozilla Security Advisories websites.