Memory leak in Mozilla Firefox - CVE-2019-11694
Published: May 21, 2019
Vulnerability details
The vulnerability exists due memory leak in Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file.. A remote attacker can create a specially crafted web page and gain access to sensitive information stored in memory on the system.
Note: the vulnerability affects Windows versions of Firefox.
Affected software
Firefox ESR
SUSE Package Hub for SUSE Linux Enterprise
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)
How to mitigate CVE-2019-11694
Mozilla Thunderbird - update to 60.7.0
Firefox ESR - update to 60.7.0
firefox-esr (Alpine package) - update to 60.7.0-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-firefox
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- Memory leak in firefox-esr (Alpine package)