Out-of-bounds read in Firefox ESR - CVE-2019-11719
Published: July 23, 2019 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Affected software
Gentoo Linux
Amazon Linux AMI
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Ansible Automation Platform
Secure Remote Services (SRS) Virtual Edition
Data Computing Appliance (DCA)
IBM Security Guardium
SUSE Package Hub for SUSE Linux Enterprise
firefox-esr (Alpine package)
nss (Red Hat package)
nss-util (Red Hat package)
nss-softokn (Red Hat package)
nspr (Red Hat package)
Red Hat OpenShift Container Platform
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2019-11719
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
firefox-esr (Alpine package) - update to 60.8.0-r0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
nss (Red Hat package) - addressed in versions 3.44.0-7.el8_0, 3.53.1-3.el7_9
nss-util (Red Hat package) - update to 3.53.1-1.el7_9
nss-softokn (Red Hat package) - update to 3.53.1-6.el7_9
Red Hat OpenShift Container Platform - update to 4.3.40
nspr (Red Hat package) - addressed in versions 4.21.0-2.el8_0, 4.25.0-2.el7_9
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
- https://access.redhat.com/errata/RHSA-2019:1951
- https://bugzilla.mozilla.org/show_bug.cgi?id=1540541
- https://security.gentoo.org/glsa/201908-12
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-21/
- https://www.mozilla.org/security/advisories/mfsa2019-22/
- https://www.mozilla.org/security/advisories/mfsa2019-23/
Related Security Bulletins
- Out-of-bounds read in Mozilla Firefox ESR
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaFirefox
- Out-of-bounds read in firefox-esr (Alpine package)
- Red Hat Enterprise Linux 7 update for nss and nspr
- Gentoo update for Mozilla Thunderbird
- Slackware Linux update for mozilla-firefox
- CentOS 7 update for nss
- Amazon Linux AMI update for nspr, nss-softokn, nss-util
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Dell EMC Secure Remote Services (SRS) Virtual Edition
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Dell EMC Unity Family, Dell EMC Unity XT Family
- Red Hat Enterprise Linux 8 update for nss and nspr
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3