Memory corruption in Mozilla Firefox - CVE-2019-9794
Published: March 21, 2019 / Updated: March 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to improper validation of command line arguments within the URI handler when opening documents with Firefox. A remote attacker can trick the victim to open a file with a specially crafted filename and execute arbitrary commands on the system.
Affected software
Firefox ESR
SUSE Package Hub for SUSE Linux Enterprise
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)
How to mitigate CVE-2019-9794
Firefox ESR - update to 60.6.0
Mozilla Thunderbird - update to 60.6.0
firefox-esr (Alpine package) - update to 60.6.1-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- Memory corruption in firefox-esr (Alpine package)