Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11707

Опубликовано: 23 июл. 2019
Источник: debian

Описание

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed67.0.3-1package
firefox-esrfixed60.7.1esr-1package
thunderbirdfixed1:60.7.2-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/#CVE-2019-11707

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-20/#CVE-2019-11707

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
redhat
около 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
nvd
почти 6 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox