Use-after-free in Mozilla Firefox - CVE-2019-9818
Published: May 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in crash generator server. A remote attacker can trick the victim to visit a specially crafted web page, trigger use-after-free error and crash the browser or execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Note: this vulnerability affects only Windows version of Firefox.
Affected software
Firefox ESR
SUSE Package Hub for SUSE Linux Enterprise
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)
How to mitigate CVE-2019-9818
Mozilla Thunderbird - update to 60.7.0
Firefox ESR - update to 60.7.0
firefox-esr (Alpine package) - update to 60.7.0-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-firefox
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- Use-after-free in firefox-esr (Alpine package)