Mozilla: Memory safety bugs fixed in Firefox 71 and Firefox ESR 68.3
Published Jan 8, 2020
8.8
HIGHCVSS 3.1
EPSS 2.28%
Description
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Affected products
-
- Version before 71StatusaffectedConstraints-
- Version
-
- Version before 68.3StatusaffectedConstraints-
- Version
-
- Version before 68.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox ESR | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
Configuration 1
- < 71.0
- < 68.3
- < 68.3
Configuration 3
- 16.04
- 18.04
- 19.10
No data.
Red Hat Enterprise Linux 6
firefox-0:68.3.0-1.el6_10
Fixed · RHSA-2019:4108
Red Hat Enterprise Linux 6
thunderbird-0:68.3.0-3.el6_10
Fixed · RHSA-2019:4205
Red Hat Enterprise Linux 7
firefox-0:68.3.0-1.el7_7
Fixed · RHSA-2019:4107
Red Hat Enterprise Linux 7
thunderbird-0:68.3.0-1.el7_7
Fixed · RHSA-2019:4148
Red Hat Enterprise Linux 8
firefox-0:68.3.0-1.el8_1
Fixed · RHSA-2019:4111
Red Hat Enterprise Linux 8
thunderbird-0:68.3.0-2.el8_1
Fixed · RHSA-2019:4195
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
firefox-0:68.4.1-1.el8_0
Fixed · RHSA-2020:0295
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
thunderbird-0:68.4.1-2.el8_0
Fixed · RHSA-2020:0292
Red Hat Enterprise Linux 5
firefox
Out of support scope
Red Hat Enterprise Linux 5
thunderbird
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox-0:68.3.0-1.el6_10 | Fixed | RHSA-2019:4108 |
| Red Hat Enterprise Linux 6 | thunderbird-0:68.3.0-3.el6_10 | Fixed | RHSA-2019:4205 |
| Red Hat Enterprise Linux 7 | firefox-0:68.3.0-1.el7_7 | Fixed | RHSA-2019:4107 |
| Red Hat Enterprise Linux 7 | thunderbird-0:68.3.0-1.el7_7 | Fixed | RHSA-2019:4148 |
| Red Hat Enterprise Linux 8 | firefox-0:68.3.0-1.el8_1 | Fixed | RHSA-2019:4111 |
| Red Hat Enterprise Linux 8 | thunderbird-0:68.3.0-2.el8_1 | Fixed | RHSA-2019:4195 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | firefox-0:68.4.1-1.el8_0 | Fixed | RHSA-2020:0295 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | thunderbird-0:68.4.1-2.el8_0 | Fixed | RHSA-2020:0292 |
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | thunderbird | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0292 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0295 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-17012 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1449736%2C1533957%2C1560667%2C1567209%2C1580288%2C1585760%2C1592502 x_refsource_MISCIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1779437 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-17012
- https://security.gentoo.org/glsa/202003-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.gentoo.org/glsa/202003-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4241-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4335-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-17012
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-37/#CVE-2019-17012
- https://www.mozilla.org/security/advisories/mfsa2019-36/ x_refsource_CONFIRMVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-37/ x_refsource_CONFIRMVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-38/ x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.