Race condition in Firefox ESR and Mozilla Firefox - CVE-2019-17021

 

Race condition in Firefox ESR and Mozilla Firefox - CVE-2019-17021

Published: January 7, 2020 / Updated: January 8, 2020


Vulnerability identifier: #VU24059
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17021
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a race condition that occurs during the initialization of a new content process. A remote attacker can exploit the race to gain access to potentially sensitive information, such as heap addresses from the parent process.

Note, this vulnerability affects Windows users only.


Affected software

Firefox ESR
Mozilla Firefox
Slackware Linux
Opensuse
Mozilla Thunderbird

How to mitigate CVE-2019-17021

Install updates from vendor's website.

Firefox ESR - update to 68.4.0
Mozilla Firefox - update to 72.0
Mozilla Thunderbird - update to 68.4.1

External References

Related Security Bulletins