Back to search
CVE-2019-17017
Published: Jan 8, 2020
Modified: Aug 5, 2024
PUBLISHED
Description
Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox ESR | affected before 68.4 |
Mozilla | Firefox | affected before 72 |
References
https://bugzilla.mozilla.org/show_bug.cgi?id=1603055
x_refsource_MISC
https://www.mozilla.org/security/advisories/mfsa2020-01/
x_refsource_CONFIRM
https://www.mozilla.org/security/advisories/mfsa2020-02/
x_refsource_CONFIRM
20200109 [SECURITY] [DSA 4600-1] firefox-esr security update
mailing-list
x_refsource_BUGTRAQ
[debian-lts-announce] 20200109 [SECURITY] [DLA 2061-1] firefox-esr security update
mailing-list
x_refsource_MLIST
DSA-4600
vendor-advisory
x_refsource_DEBIAN
USN-4234-1
vendor-advisory
x_refsource_UBUNTU
20200112 [slackware-security] mozilla-thunderbird (SSA:2020-010-01)
mailing-list
x_refsource_BUGTRAQ
RHSA-2020:0085
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0086
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0111
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0060
vendor-advisory
x_refsource_SUSE
RHSA-2020:0120
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0123
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0127
vendor-advisory
x_refsource_REDHAT
USN-4241-1
vendor-advisory
x_refsource_UBUNTU
DSA-4603
vendor-advisory
x_refsource_DEBIAN
20200120 [SECURITY] [DSA 4603-1] thunderbird security update
mailing-list
x_refsource_BUGTRAQ
[debian-lts-announce] 20200120 [SECURITY] [DLA 2071-1] thunderbird security update
mailing-list
x_refsource_MLIST
openSUSE-SU-2020:0094
vendor-advisory
x_refsource_SUSE
RHSA-2020:0292
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0295
vendor-advisory
x_refsource_REDHAT
GLSA-202003-02
vendor-advisory
x_refsource_GENTOO
USN-4335-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now