PT-2019-5128 · Mozilla+5 · Firefox+5

J.C. Jones

·

Published

2019-12-03

·

Updated

2024-12-12

·

CVE-2019-11756

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 71
Description The issue is related to improper refcounting of soft token session objects, which could cause a use-after-free and crash, likely limited to a denial of service. It may also allow a remote attacker to gain unauthorized access to confidential data, cause a denial of service, and impact data integrity.
Recommendations For versions prior to 71, update to version 71 or later to resolve the issue.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3239
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-01795
CESA-2020_3280
CESA-2020_4076
CVE-2019-11756
OESA-2021-1059
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:3280
RHSA-2020:4076
RHSA-2020_3280
RHSA-2020_4076
RHSA-2021:0758
RHSA-2021:0876
RHSA-2021:1026
RLSA-2020:3280
USN-4216-1
USN-4216-2

Affected Products

Alt Linux
Centos
Firefox
Red Hat
Rocky Linux
Ubuntu