First published: Tue Oct 22 2019(Updated: )
Mozilla developers and community members Bob Clary, Jason Kratzer, Aaron Klotz, Iain Ireland, Tyson Smith, Christian Holler, Steve Fink, Honza Bambas, Byron Campen, and Cristian Brindusan reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <0:68.2.0-4.el6_10 | 0:68.2.0-4.el6_10 |
redhat/thunderbird | <0:68.2.0-2.el6_10 | 0:68.2.0-2.el6_10 |
redhat/firefox | <0:68.2.0-1.el7_7 | 0:68.2.0-1.el7_7 |
redhat/thunderbird | <0:68.2.0-1.el7_7 | 0:68.2.0-1.el7_7 |
redhat/firefox | <0:68.2.0-2.el8_0 | 0:68.2.0-2.el8_0 |
redhat/thunderbird | <0:68.2.0-1.el8_0 | 0:68.2.0-1.el8_0 |
redhat/firefox | <68.2 | 68.2 |
redhat/thunderbird | <68.2 | 68.2 |
Mozilla Thunderbird | <68.2 | 68.2 |
Mozilla Firefox ESR | <68.2 | 68.2 |
Mozilla Firefox | <70 | 70 |
Mozilla Firefox | <70.0 | |
Mozilla Firefox ESR | <68.2 | |
Mozilla Thunderbird | <68.2 | |
Canonical Ubuntu Linux | =16.04 | |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/firefox | <70.0 | 70.0 |
ubuntu/firefox | <70.0+ | 70.0+ |
ubuntu/thunderbird | <1:68.2.1+ | 1:68.2.1+ |
ubuntu/thunderbird | <1:68.2.1+ | 1:68.2.1+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <1:68.2.0+ | 1:68.2.0+ |
ubuntu/thunderbird | <68.2 | 68.2 |
ubuntu/thunderbird | <1:68.7.0+ | 1:68.7.0+ |
debian/firefox | 125.0.3-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.10.0esr-1~deb10u1 115.7.0esr-1~deb11u1 115.10.0esr-1~deb11u1 115.7.0esr-1~deb12u1 115.10.0esr-1~deb12u1 115.10.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.10.1-1~deb10u1 1:115.7.0-1~deb11u1 1:115.10.1-1~deb11u1 1:115.7.0-1~deb12u1 1:115.10.1-1~deb12u1 1:115.10.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2019-11764 is a vulnerability discovered in Firefox 69 and Firefox ESR 68.1 that allows memory safety bugs to be exploited.
CVE-2019-11764 has a severity rating of 8.8, which is classified as critical.
Firefox versions 69 and Firefox ESR 68.1 are affected by CVE-2019-11764.
To fix CVE-2019-11764, you should update Firefox to version 68.2 or later.
You can find more information about CVE-2019-11764 on the Mozilla Bugzilla and Mozilla security advisories websites.