CVE-2019-9817: Medium severity Mozilla Thunderbird vulnerability
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 67 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 155.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb12u1Fixed in 140.14.0esr-1~deb12u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.14.0esr-1~deb13u1Fixed in 140.14.0esr-2Fixed in 140.15.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.14.0esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.14.0esr-1~deb13u1Fixed in 1:140.14.0esr-1Fixed in 1:153.2.0esr-1 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 67 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 60.7
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-9821
- CVE-2019-11695
- CVE-2019-11696
- CVE-2019-11697
- CVE-2019-11700
- CVE-2019-11699
- CVE-2019-11701
- CVE-2019-9814
Frequently Asked Questions
What is the severity of vulnerability CVE-2019-9817?
The severity of vulnerability CVE-2019-9817 is high.
Which software versions are affected by CVE-2019-9817?
Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7 are affected by CVE-2019-9817.
How can CVE-2019-9817 be exploited?
CVE-2019-9817 can be exploited by reading images from a different domain using a canvas object.
What is the risk of CVE-2019-9817?
CVE-2019-9817 allows attackers to steal image data from a different site in violation of same-origin policy.
Where can I find more information about CVE-2019-9817?
More information about CVE-2019-9817 can be found at the following references: [1] [2] [3].