Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17011

Опубликовано: 08 янв. 2020
Источник: debian

Описание

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed71.0-1package
firefox-esrfixed68.3.0esr-1package
thunderbirdfixed1:68.3.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-36/#CVE-2019-17011

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-37/#CVE-2019-17011

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-38/#CVE-2019-17011

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
redhat
больше 6 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
nvd
больше 6 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
github
около 4 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибкой извлечения документа из DocShell, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании