CVE-2019-17021: Race Condition
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. Note: this issue only occurs on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Other sources
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. Note: this issue only occurs on Windows. Other operating systems are unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17021?
CVE-2019-17021 is a vulnerability that occurs during the initialization of a new content process in Firefox ESR and Firefox.
How does CVE-2019-17021 affect Mozilla Firefox?
CVE-2019-17021 affects Firefox ESR versions prior to 68.4 and Firefox versions prior to 72.
Which operating systems are affected by CVE-2019-17021?
CVE-2019-17021 only affects Windows operating systems.
What is the severity of CVE-2019-17021?
The severity of CVE-2019-17021 is medium with a CVSS score of 5.3.
How can I fix the CVE-2019-17021 vulnerability?
To fix the CVE-2019-17021 vulnerability, update Firefox ESR to version 68.4 or later, and update Firefox to version 72 or later.