Mozilla: Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1
Published Sep 27, 2019
9.8
CRITICALCVSS 3.1
EPSS 1.18%
Description
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<69
- Version
-
- Version unspecifiedStatusaffectedConstraints<68.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox ESR | n/a |
|
No data.
Red Hat Enterprise Linux 8
firefox-0:68.1.0-1.el8_0
Fixed · RHSA-2019:2663
Red Hat Enterprise Linux 5
firefox
Out of support scope
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | firefox-0:68.1.0-1.el8_0 | Fixed | RHSA-2019:2663 |
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11735 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1561404%2C1561484%2C1568047%2C1561912%2C1565744%2C1568858%2C1570358 x_refsource_MISCIssue TrackingNot ApplicableVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1748661 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-11735
- https://www.cve.org/CVERecord?id=CVE-2019-11735
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11735
- https://www.mozilla.org/security/advisories/mfsa2019-25/ x_refsource_CONFIRMVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-26/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-11735 | Vendor Advisory | |
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1561404%2C1561484%2C1568047%2C1561912%2C1565744%2C1568858%2C1570358 | x_refsource_MISCIssue TrackingNot ApplicableVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1748661 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11735 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-11735 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11735 | ||
| https://www.mozilla.org/security/advisories/mfsa2019-25/ | x_refsource_CONFIRMVendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2019-26/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.