PT-2019-4869 · Mozilla+5 · Firefox+5

Bob Clary

+2

·

Published

2019-12-03

·

Updated

2024-12-12

·

CVE-2019-17024

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 72 Firefox ESR versions prior to 68.4
Description The issue is related to a memory safety bug that can be exploited by a remote attacker to access confidential data, compromise data integrity, and cause a denial of service. The bug is associated with a buffer copy error from memory without checking its size. Some of these bugs have shown evidence of memory corruption, and it is presumed that with sufficient effort, they could have been exploited to run arbitrary code.
Recommendations For Firefox versions prior to 72, update to version 72 or later to resolve the issue. For Firefox ESR versions prior to 68.4, update to version 68.4 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1013
ALT-PU-2020-1032
ALT-PU-2020-1110
ALT-PU-2020-1166
ALT-PU-2020-1515
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-01456
CESA-2020_0085
CESA-2020_0086
CESA-2020_0111
CESA-2020_0120
CESA-2020_0123
CESA-2020_0127
CVE-2019-17024
DLA-2061-1
DLA-2071-1
DSA-4600-1
DSA-4603-1
MGASA-2020-0027
MGASA-2020-0034
OPENSUSE-SU-2020:0060-1
OPENSUSE-SU-2020:0094-1
OPENSUSE-SU-2020_0060-1
OPENSUSE-SU-2020_0094-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:0085
RHSA-2020:0086
RHSA-2020:0111
RHSA-2020:0120
RHSA-2020:0123
RHSA-2020:0127
RHSA-2020:0292
RHSA-2020:0295
RHSA-2020_0085
RHSA-2020_0086
RHSA-2020_0111
RHSA-2020_0120
RHSA-2020_0123
RHSA-2020_0127
SUSE-SU-2020:0068-1
SUSE-SU-2020:0078-1
SUSE-SU-2020:0142-1
SUSE-SU-2020:14268-1
USN-4234-1
USN-4234-2
USN-4241-1
USN-4335-1

Affected Products

Alt Linux
Centos
Firefox
Red Hat
Suse
Ubuntu