Mozilla: Type inference is incorrect for constructors entered through on-stack replacement with IonMonkey
Published Apr 26, 2019
9.8
CRITICALCVSS 3.1
EPSS 19.91%
Description
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Affected products
-
Affected
- ≥ unspecified, < 66
-
Affected
- ≥ unspecified, < 60.6
-
Affected
- ≥ unspecified, < 60.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mozilla | Firefox | unknown | Affected
|
| Mozilla | Firefox ESR | unknown | Affected
|
| Mozilla | Thunderbird | unknown | Affected
|
Configuration 1
Configuration 2
- 8.0
- 8.1
- 8.2
- 8.4
- 8.2
- 8.4
- 8.2
- 8.4
No data.
Red Hat Enterprise Linux 6
firefox-0:60.6.0-3.el6_10
Fixed · RHSA-2019:0623
Red Hat Enterprise Linux 6
thunderbird-0:60.6.1-1.el6_10
Fixed · RHSA-2019:0680
Red Hat Enterprise Linux 7
firefox-0:60.6.0-3.el7_6
Fixed · RHSA-2019:0622
Red Hat Enterprise Linux 7
thunderbird-0:60.6.1-1.el7_6
Fixed · RHSA-2019:0681
Red Hat Enterprise Linux 8
firefox-0:60.6.1-1.el8
Fixed · RHSA-2019:0966
Red Hat Enterprise Linux 8
thunderbird-0:60.6.1-1.el8
Fixed · RHSA-2019:1144
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox-0:60.6.0-3.el6_10 | Fixed | RHSA-2019:0623 |
| Red Hat Enterprise Linux 6 | thunderbird-0:60.6.1-1.el6_10 | Fixed | RHSA-2019:0680 |
| Red Hat Enterprise Linux 7 | firefox-0:60.6.0-3.el7_6 | Fixed | RHSA-2019:0622 |
| Red Hat Enterprise Linux 7 | thunderbird-0:60.6.1-1.el7_6 | Fixed | RHSA-2019:0681 |
| Red Hat Enterprise Linux 8 | firefox-0:60.6.1-1.el8 | Fixed | RHSA-2019:0966 |
| Red Hat Enterprise Linux 8 | thunderbird-0:60.6.1-1.el8 | Fixed | RHSA-2019:1144 |
No package ranges for this CVE.
Remediation
Red Hat statement
In general, this flaw be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
References (12)
- https://access.redhat.com/errata/RHSA-2019:0966 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1144 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-9791 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1530958 x_refsource_MISCExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1690676 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19153 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-9791
- https://www.cve.org/CVERecord?id=CVE-2019-9791
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9791
- https://www.mozilla.org/security/advisories/mfsa2019-07/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-08/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-11/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:0966 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2019:1144 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-9791 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1530958 | x_refsource_MISCExploitIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1690676 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19153 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-9791 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-9791 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9791 | ||
| https://www.mozilla.org/security/advisories/mfsa2019-07/ | x_refsource_MISCVendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2019-08/ | x_refsource_MISCVendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2019-11/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data