Mozilla: Ionmonkey type confusion with __proto__ mutations
Published Apr 26, 2019
8.8
HIGHCVSS 3.0
EPSS 7.39%
Description
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<66.0.1
- Version
-
- Version unspecifiedStatusaffectedConstraints<60.6.1
- Version
-
- Version unspecifiedStatusaffectedConstraints<60.6.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox ESR | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
No data.
Red Hat Enterprise Linux 6
firefox-0:60.6.1-1.el6_10
Fixed · RHSA-2019:0672
Red Hat Enterprise Linux 6
thunderbird-0:60.6.1-1.el6_10
Fixed · RHSA-2019:0680
Red Hat Enterprise Linux 7
firefox-0:60.6.1-1.el7_6
Fixed · RHSA-2019:0671
Red Hat Enterprise Linux 7
thunderbird-0:60.6.1-1.el7_6
Fixed · RHSA-2019:0681
Red Hat Enterprise Linux 8
firefox-0:60.6.1-1.el8
Fixed · RHSA-2019:0966
Red Hat Enterprise Linux 8
thunderbird-0:60.6.1-1.el8
Fixed · RHSA-2019:1144
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox-0:60.6.1-1.el6_10 | Fixed | RHSA-2019:0672 |
| Red Hat Enterprise Linux 6 | thunderbird-0:60.6.1-1.el6_10 | Fixed | RHSA-2019:0680 |
| Red Hat Enterprise Linux 7 | firefox-0:60.6.1-1.el7_6 | Fixed | RHSA-2019:0671 |
| Red Hat Enterprise Linux 7 | thunderbird-0:60.6.1-1.el7_6 | Fixed | RHSA-2019:0681 |
| Red Hat Enterprise Linux 8 | firefox-0:60.6.1-1.el8 | Fixed | RHSA-2019:0966 |
| Red Hat Enterprise Linux 8 | thunderbird-0:60.6.1-1.el8 | Fixed | RHSA-2019:1144 |
No package ranges for this CVE.
Remediation
Red Hat statement
In general, this flaw can be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
References (11)
- https://access.redhat.com/errata/RHSA-2019:0966 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:1144 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-9813 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1538006 x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1692182 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-9813
- https://www.cve.org/CVERecord?id=CVE-2019-9813
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-10/#CVE-2019-9813
- https://www.mozilla.org/security/advisories/mfsa2019-09/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-10/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-12/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:0966 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:1144 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2019-9813 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1538006 | x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1692182 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-9813 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-9813 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-10/#CVE-2019-9813 | ||
| https://www.mozilla.org/security/advisories/mfsa2019-09/ | x_refsource_MISCVendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2019-10/ | x_refsource_MISCVendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2019-12/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.