First published: Tue Jan 07 2020(Updated: )
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <72.0 | |
Mozilla Firefox ESR | <68.4 | |
Microsoft Windows | ||
openSUSE Leap | =15.1 | |
Mozilla Firefox ESR | <68.4 | 68.4 |
<68.4.1 | 68.4.1 | |
<68.4 | 68.4 | |
<72 | 72 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-17021 is a vulnerability that occurs during the initialization of a new content process in Firefox ESR and Firefox.
CVE-2019-17021 affects Firefox ESR versions prior to 68.4 and Firefox versions prior to 72.
CVE-2019-17021 only affects Windows operating systems.
The severity of CVE-2019-17021 is medium with a CVSS score of 5.3.
To fix the CVE-2019-17021 vulnerability, update Firefox ESR to version 68.4 or later, and update Firefox to version 72 or later.