Race condition in Mozilla Firefox - CVE-2019-9815
Published: May 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to enabled hyperthreading in applications running untrusted code in a thread through a new sysctl on macOS. A remote attacker can perform timing attack, similar to previous Spectre attacks and execute arbitrary code on the target system.
The vulnerability affects macOS users.
For this mitigation to take effect, users must install macOS 10.14.5.
Affected software
Firefox ESR
SUSE Package Hub for SUSE Linux Enterprise
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)
How to mitigate CVE-2019-9815
Mozilla Thunderbird - update to 60.7.0
Firefox ESR - update to 60.7.0
firefox-esr (Alpine package) - update to 60.7.0-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-firefox
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- Race condition in firefox-esr (Alpine package)