PT-2019-2969 · Mozilla+6 · Thunderbird+8

Freddy

+1

·

Published

2019-06-19

·

Updated

2025-09-29

·

CVE-2019-11708

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 67.0.4 Mozilla Firefox ESR versions prior to 60.7.2 Thunderbird versions prior to 60.7.2
Description The issue is caused by insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes. This can result in the non-sandboxed parent process opening web content chosen by a compromised child process, potentially allowing attackers to execute arbitrary code on the user's computer when combined with additional vulnerabilities.
Recommendations For Mozilla Firefox versions prior to 67.0.4, update to version 67.0.4 or later. For Mozilla Firefox ESR versions prior to 60.7.2, update to version 60.7.2 or later. For Thunderbird versions prior to 60.7.2, update to version 60.7.2 or later. As a temporary workaround, consider restricting access to the Prompt:Open IPC message to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_0595
ALSA-2025_0693
ALSA-2025_16880
ALT-PU-2019-2118
ALT-PU-2019-2122
ALT-PU-2019-2130
ALT-PU-2019-2132
ALT-PU-2019-2133
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
BDU:2019-02947
CESA-2019_1603
CESA-2019_1604
CESA-2019_1623
CESA-2019_1624
CESA-2019_1626
CESA-2019_1696
CVE-2019-11708
DLA-1836-1
DSA-4471-1
DSA-4474-1
ELSA-2019-1603
ELSA-2019-1604
ELSA-2019-1623
ELSA-2019-1624
ELSA-2019-1626
ELSA-2019-1696
MGASA-2019-0201
MGASA-2019-0202
MGASA-2020-0009
OPENSUSE-SU-2019:1595-1
OPENSUSE-SU-2019:1606-1
OPENSUSE-SU-2019:1664-1
OPENSUSE-SU-2019_1594-1
OPENSUSE-SU-2019_1595-1
OPENSUSE-SU-2019_1606-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2019:1603
RHSA-2019:1604
RHSA-2019:1623
RHSA-2019:1624
RHSA-2019:1626
RHSA-2019:1696
RHSA-2019_1603
RHSA-2019_1604
RHSA-2019_1623
RHSA-2019_1624
RHSA-2019_1626
RHSA-2019_1696
SUSE-SU-2019:14124-1
SUSE-SU-2019:1682-1
SUSE-SU-2019:1683-1
SUSE-SU-2019:1684-1
SUSE-SU-2019_14124-1
SUSE-SU-2019_1682-1
SUSE-SU-2019_1684-1
USN-4032-1
USN-4045-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Tor Browser
Ubuntu