First published: Tue Jan 07 2020(Updated: )
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <68.4.1 | 68.4.1 |
Firefox | <72 | 72 |
Firefox ESR | <68.4 | 68.4 |
Firefox | <72.0 | |
Firefox ESR | <68.4 | |
Microsoft Windows Operating System | ||
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-17021 is a vulnerability that occurs during the initialization of a new content process in Firefox ESR and Firefox.
CVE-2019-17021 affects Firefox ESR versions prior to 68.4 and Firefox versions prior to 72.
CVE-2019-17021 only affects Windows operating systems.
The severity of CVE-2019-17021 is medium with a CVSS score of 5.3.
To fix the CVE-2019-17021 vulnerability, update Firefox ESR to version 68.4 or later, and update Firefox to version 72 or later.