Mozilla: Improper bounds checks when Spectre mitigations are disabled
Published Apr 26, 2019
5.9
MEDIUMCVSS 3.0
EPSS 1.63%
Description
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have explicitly disabled Spectre mitigations. *Note: Spectre mitigations are currently enabled for all users by default settings.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<66
- Version
-
- Version unspecifiedStatusaffectedConstraints<60.6
- Version
-
- Version unspecifiedStatusaffectedConstraints<60.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox ESR | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
- < 66.0
- < 60.6
- < 60.6
No data.
Red Hat Enterprise Linux 6
firefox-0:60.6.0-3.el6_10
Fixed · RHSA-2019:0623
Red Hat Enterprise Linux 6
thunderbird-0:60.6.1-1.el6_10
Fixed · RHSA-2019:0680
Red Hat Enterprise Linux 7
firefox-0:60.6.0-3.el7_6
Fixed · RHSA-2019:0622
Red Hat Enterprise Linux 7
thunderbird-0:60.6.1-1.el7_6
Fixed · RHSA-2019:0681
Red Hat Enterprise Linux 8
firefox-0:60.6.1-1.el8
Fixed · RHSA-2019:0966
Red Hat Enterprise Linux 8
thunderbird-0:60.6.1-1.el8
Fixed · RHSA-2019:1144
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox-0:60.6.0-3.el6_10 | Fixed | RHSA-2019:0623 |
| Red Hat Enterprise Linux 6 | thunderbird-0:60.6.1-1.el6_10 | Fixed | RHSA-2019:0680 |
| Red Hat Enterprise Linux 7 | firefox-0:60.6.0-3.el7_6 | Fixed | RHSA-2019:0622 |
| Red Hat Enterprise Linux 7 | thunderbird-0:60.6.1-1.el7_6 | Fixed | RHSA-2019:0681 |
| Red Hat Enterprise Linux 8 | firefox-0:60.6.1-1.el8 | Fixed | RHSA-2019:0966 |
| Red Hat Enterprise Linux 8 | thunderbird-0:60.6.1-1.el8 | Fixed | RHSA-2019:1144 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/errata/RHSA-2019:0966 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:1144 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-9793 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1528829 x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1690678 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-9793
- https://www.cve.org/CVERecord?id=CVE-2019-9793
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9793
- https://www.mozilla.org/security/advisories/mfsa2019-07/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-08/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-11/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:0966 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:1144 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2019-9793 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1528829 | x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1690678 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-9793 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-9793 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9793 | ||
| https://www.mozilla.org/security/advisories/mfsa2019-07/ | x_refsource_MISCVendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2019-08/ | x_refsource_MISCVendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2019-11/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.