First published: Tue Mar 19 2019(Updated: )
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have explicitly disabled Spectre mitigations. *Note: Spectre mitigations are currently enabled for all users by default settings.* External Reference: <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9793">https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9793</a>
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <60.6 | 60.6 |
Mozilla Firefox ESR | <60.6 | 60.6 |
Mozilla Firefox | <66 | 66 |
Mozilla Firefox | <66.0 | |
Mozilla Firefox ESR | <60.6 | |
Mozilla Thunderbird | <60.6 | |
debian/firefox | 132.0.2-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.4.0esr-1~deb11u1 128.3.1esr-1~deb12u1 128.4.0esr-1~deb12u1 128.3.1esr-2 128.4.0esr-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.4.3esr-1~deb11u1 1:115.16.0esr-1~deb12u1 1:128.4.0esr-1~deb12u1 1:128.4.2esr-1 1:128.4.3esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-9793 is a vulnerability that removes some bounds checking for string, array, or typed array accesses in JavaScript if Spectre mitigations have been disabled.
CVE-2019-9793 has a severity rating of high.
CVE-2019-9793 affects Mozilla Firefox versions up to and excluding 66.0.
CVE-2019-9793 affects Mozilla Firefox ESR versions up to and excluding 60.6.
To fix CVE-2019-9793 in Firefox, update to version 66.0 or later.
To fix CVE-2019-9793 in Firefox ESR, update to version 60.6 or later.