First published: Tue May 21 2019(Updated: )
Mozilla developers and community members Olli Pettay, Bogdan Tara, Jan de Mooij, Jason Kratzer, Jan Varga, Gary Kwong, Tim Guan-tin Chien, Tyson Smith, Ronald Crane, and Ted Campbell reported memory safety bugs present in Firefox 66 and Firefox ESR 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <60.7 | 60.7 |
Mozilla Firefox ESR | <60.7 | 60.7 |
Mozilla Firefox | <67 | 67 |
Mozilla Firefox | <67.0 | |
Mozilla Firefox ESR | <60.7 | |
Mozilla Thunderbird | <60.7 | |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/firefox | <67.0 | 67.0 |
ubuntu/firefox | <67.0+ | 67.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
ubuntu/thunderbird | <60.7 | 60.7 |
ubuntu/thunderbird | <1:60.7.0+ | 1:60.7.0+ |
debian/firefox | 125.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.10.0esr-1~deb10u1 115.7.0esr-1~deb11u1 115.10.0esr-1~deb11u1 115.7.0esr-1~deb12u1 115.10.0esr-1~deb12u1 115.8.0esr-1 115.10.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.10.1-1~deb10u1 1:115.7.0-1~deb11u1 1:115.10.1-1~deb11u1 1:115.7.0-1~deb12u1 1:115.10.1-1~deb12u1 1:115.10.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The severity of CVE-2019-9800 is critical, with a severity value of 9.
Firefox versions up to 67.0 are affected by CVE-2019-9800.
Firefox ESR versions up to 60.7 are affected by CVE-2019-9800.
Thunderbird versions up to 60.7 are affected by CVE-2019-9800.
More information about CVE-2019-9800 can be found at the following references: [Reference 1](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1540166%2C1534593%2C1546327%2C1540136%2C1538736%2C1538042%2C1535612%2C1499719%2C1499108%2C1538619%2C1535194%2C1516325%2C1542324%2C1542097%2C1532465%2C1533554%2C1541580), [Reference 2](https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/), [Reference 3](https://www.mozilla.org/security/advisories/mfsa2019-13/).