Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17011

Опубликовано: 08 янв. 2020
Источник: debian
EPSS Низкий

Описание

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed71.0-1package
firefox-esrfixed68.3.0esr-1package
thunderbirdfixed1:68.3.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-36/#CVE-2019-17011

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-37/#CVE-2019-17011

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-38/#CVE-2019-17011

EPSS

Процентиль: 80%
0.01329
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
redhat
около 6 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
nvd
около 6 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
github
больше 3 лет назад

Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибкой извлечения документа из DocShell, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 80%
0.01329
Низкий