Risk | High |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2019-11709 |
CWE-ID | CWE-119 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
firefox-esr (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU33030
Risk: High
CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2019-11709
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
MitigationInstall update from vendor's website.
Vulnerable software versionsfirefox-esr (Alpine package): 60.4.0-r0 - 68.0-r0
CPE2.3https://git.alpinelinux.org/aports/commit/?id=df118d5706ba2d60b54d1285b0c2544abd2dc984
https://git.alpinelinux.org/aports/commit/?id=2158f01e86aa6551e5e429999acda15151214929
https://git.alpinelinux.org/aports/commit/?id=dbc43022e7aaaeb53d19f31c2ba03ab99f95c608
https://git.alpinelinux.org/aports/commit/?id=2619d83127353533f980218076d6c0c02fe7c198
https://git.alpinelinux.org/aports/commit/?id=a0c09e8b7fb341082bdaced72c40714ba91f932a
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.