CVE-2019-17017: High severity Mozilla Thunderbird vulnerability
Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17017?
CVE-2019-17017 is a vulnerability that can result in a crash due to a missing case handling object types, potentially allowing an attacker to run arbitrary code.
Which software is affected by CVE-2019-17017?
Mozilla Firefox ESR version up to 68.4, Mozilla Thunderbird version up to 68.4.1, and Mozilla Firefox version up to 72 are affected by CVE-2019-17017.
What is the severity of CVE-2019-17017?
CVE-2019-17017 has a severity level of high (7).
How can CVE-2019-17017 be exploited?
CVE-2019-17017 could be exploited to run arbitrary code, but it would require a significant amount of effort.
How can I fix CVE-2019-17017?
To fix CVE-2019-17017, update Mozilla Firefox ESR to version 68.4 or later, update Mozilla Thunderbird to version 68.4.1 or later, or update Mozilla Firefox to version 72 or later.