Race condition in Mozilla Firefox and Firefox ESR - CVE-2019-17021

 

Race condition in Mozilla Firefox and Firefox ESR - CVE-2019-17021

Published: January 7, 2020 / Updated: January 8, 2020


Vulnerability identifier: #VU24059
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-17021
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Mozilla
Affected software:
Mozilla Firefox
Firefox ESR

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a race condition that occurs during the initialization of a new content process. A remote attacker can exploit the race to gain access to potentially sensitive information, such as heap addresses from the parent process.

Note, this vulnerability affects Windows users only.


How to mitigate CVE-2019-17021

Install updates from vendor's website.

Sources