PT-2019-3442 · Mozilla+6 · Firefox+8

Samuel Groß

·

Published

2018-07-05

·

Updated

2025-09-29

·

CVE-2019-11707

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 67.0.3 Firefox ESR versions prior to 60.7.1 Thunderbird versions prior to 60.7.2
Description A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. The vulnerability is related to JavaScript objects manipulation and issues in Array.pop, allowing remote attackers to cause a denial of service (crash) or potentially execute arbitrary code.
Recommendations For Firefox versions prior to 67.0.3, update to version 67.0.3 or later. For Firefox ESR versions prior to 60.7.1, update to version 60.7.1 or later. For Thunderbird versions prior to 60.7.2, update to version 60.7.2 or later. As a temporary workaround, consider disabling the Array.pop method until a patch is available. Restrict access to JavaScript objects to minimize the risk of exploitation. Avoid using vulnerable JavaScript code until the issue is resolved.

Exploit

Fix

DoS

Type Confusion

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2018-1985
ALT-PU-2019-2091
ALT-PU-2019-2092
ALT-PU-2019-2098
ALT-PU-2019-2130
ALT-PU-2019-2132
ALT-PU-2019-2231
ALT-PU-2019-2233
BDU:2019-03613
CESA-2019_1603
CESA-2019_1604
CESA-2019_1623
CESA-2019_1624
CESA-2019_1626
CESA-2019_1696
CVE-2019-11707
DLA-1829-1
DLA-1836-1
DSA-4466-1
DSA-4471-1
ELSA-2019-1603
ELSA-2019-1604
ELSA-2019-1623
ELSA-2019-1624
ELSA-2019-1626
ELSA-2019-1696
MGASA-2019-0198
MGASA-2019-0201
MGASA-2020-0009
OPENSUSE-SU-2019:1593-1
OPENSUSE-SU-2019:1606-1
OPENSUSE-SU-2019:1664-1
OPENSUSE-SU-2019_1593-1
OPENSUSE-SU-2019_1594-1
OPENSUSE-SU-2019_1606-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2019:1603
RHSA-2019:1604
RHSA-2019:1623
RHSA-2019:1624
RHSA-2019:1626
RHSA-2019:1696
RHSA-2019_1603
RHSA-2019_1604
RHSA-2019_1623
RHSA-2019_1624
RHSA-2019_1626
RHSA-2019_1696
SUSE-RU-2019:1625-1
SUSE-SU-2019:14124-1
SUSE-SU-2019:1629-1
SUSE-SU-2019:1683-1
SUSE-SU-2019_14124-1
SUSE-SU-2019_1629-1
USN-4020-1
USN-4045-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Tor Browser
Ubuntu