Race condition in Firefox ESR and Mozilla Firefox - CVE-2019-17021
Published: January 7, 2020 / Updated: January 8, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a race condition that occurs during the initialization of a new content process. A remote attacker can exploit the race to gain access to potentially sensitive information, such as heap addresses from the parent process.
Note, this vulnerability affects Windows users only.
Affected software
Mozilla Firefox
Slackware Linux
Opensuse
Mozilla Thunderbird
How to mitigate CVE-2019-17021
Mozilla Firefox - update to 72.0
Mozilla Thunderbird - update to 68.4.1