CVE-2019-11707

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2019-11707
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11707.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-11707
Related
Published
2019-07-23T14:15:15Z
Modified
2024-09-11T04:27:28.214507Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

References

Affected packages

Alpine:v3.10 / mozjs60

Package

Name
mozjs60
Purl
pkg:apk/alpine/mozjs60?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.7.2-r0

Affected versions

60.*

60.0.2-r0
60.0.2-r2
60.0.2-r3
60.0.2-r4
60.6.1-r0
60.6.1-r1
60.6.2-r0
60.7.0-r0

Alpine:v3.11 / mozjs60

Package

Name
mozjs60
Purl
pkg:apk/alpine/mozjs60?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.7.2-r0

Affected versions

60.*

60.0.2-r0
60.0.2-r2
60.0.2-r3
60.0.2-r4
60.6.1-r0
60.6.1-r1
60.6.2-r0
60.7.0-r0

Alpine:v3.12 / mozjs60

Package

Name
mozjs60
Purl
pkg:apk/alpine/mozjs60?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.7.2-r0

Affected versions

60.*

60.0.2-r0
60.0.2-r2
60.0.2-r3
60.0.2-r4
60.6.1-r0
60.6.1-r1
60.6.2-r0
60.7.0-r0

Debian:11 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.7.1esr-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.7.1esr-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.7.1esr-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:60.7.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:60.7.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:60.7.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}