PT-2019-4865 · Mozilla+5 · Firefox+5
Bo13Oy
·
Published
2019-12-03
·
Updated
2024-12-12
·
CVE-2019-17017
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox ESR versions prior to 68.4
Firefox versions prior to 72
Description
A type confusion vulnerability could occur due to a missing case handling object types, resulting in a crash. It is presumed that with enough effort, this issue could be exploited to run arbitrary code, potentially allowing a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations
For Firefox ESR versions prior to 68.4, update to version 68.4 or later.
For Firefox versions prior to 72, update to version 72 or later.
Exploit
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Firefox
Red Hat
Suse
Ubuntu