HIGH
Mozilla: Memory safety bugs fixed in Firefox 71
Published Jan 8, 2020
8.8
HIGHCVSS 3.1
EPSS 0.98%
Description
Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 71.
Affected products
-
- Version before 71StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 5
firefox
Out of support scope
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2019-17013 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1298509%2C1472328%2C1577439%2C1577937%2C1580320%2C1584195%2C1585106%2C1586293%2C1593865%2C1594181 x_refsource_MISCExploitIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1779441 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-17013
- https://www.cve.org/CVERecord?id=CVE-2019-17013
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-36/#CVE-2019-17013
- https://www.mozilla.org/security/advisories/mfsa2019-36/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-17013 | Vendor Advisory | |
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1298509%2C1472328%2C1577439%2C1577937%2C1580320%2C1584195%2C1585106%2C1586293%2C1593865%2C1594181 | x_refsource_MISCExploitIssue TrackingPatchVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1779441 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-17013 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-17013 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-36/#CVE-2019-17013 | ||
| https://www.mozilla.org/security/advisories/mfsa2019-36/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jan 8, 2020
Updated Aug 5, 2024
Reserved Sep 30, 2019
Link CVE-2019-17013
CISA Vulnrichment
Updated n/a