CVE-2019-9795: Critical severity Mozilla Firefox vulnerability
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 66 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.6 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.6 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.11.0esr-1~deb11u1Fixed in 140.10.2esr-1~deb12u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.10.2esr-1~deb13u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.11.0esr-1Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.10.1esr-1~deb12u1Fixed in 1:140.11.0esr-1~deb12u1Fixed in 1:140.10.1esr-1~deb13u1Fixed in 1:140.11.0esr-1~deb13u1Fixed in 1:140.11.0esr-1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-9795?
CVE-2019-9795 is a vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash in Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
What is the severity of CVE-2019-9795?
CVE-2019-9795 has a severity rating of critical with a value of 9.8.
Which software versions are affected by CVE-2019-9795?
CVE-2019-9795 affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
How can CVE-2019-9795 be exploited?
CVE-2019-9795 can be potentially exploited by malicious JavaScript to trigger a crash.
Where can I find more information about CVE-2019-9795?
More information about CVE-2019-9795 can be found at the following references: [Link 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1514682), [Link 2](https://www.mozilla.org/en-US/security/advisories/mfsa2019-07/), [Link 3](https://www.mozilla.org/security/advisories/mfsa2019-07/)