Back

CRITICAL

Mozilla: Type inference is incorrect for constructors entered through on-stack replacement with IonMonkey

Published Apr 26, 2019

Description

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Affected products

Remediation

Red Hat statement

In general, this flaw be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Apr 26, 2019
Updated Aug 4, 2024
Reserved Mar 14, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Critical
Public date Mar 20, 2019
Bugzilla 1690676

ENISA EUVD

Assigner mozilla
Published Apr 26, 2019
Updated Aug 4, 2024

GitHub

No data