Back

CRITICAL

Mozilla: IonMonkey leaks JS_OPTIMIZED_OUT magic value to script

Published Apr 26, 2019

Description

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Affected products

Remediation

Red Hat statement

In general, this flaw be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Apr 26, 2019
Updated Aug 4, 2024
Reserved Mar 14, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Mar 20, 2019