PT-2020-1288 · Mozilla+5 · Firefox+7

Tjr

·

Published

2020-01-08

·

Updated

2025-09-29

·

CVE-2019-17026

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 72.0.1 Firefox ESR versions prior to 68.4.1 Thunderbird versions prior to 68.4.1
Description The issue is related to a type confusion vulnerability in the IonMonkey JIT compiler, which could allow a remote attacker to gain access to confidential data, compromise data integrity, and cause a denial of service using a specially crafted web page. There have been targeted attacks in the wild abusing this flaw. The vulnerability can be exploited by tricking users into visiting a malicious site, potentially allowing remote attackers to take complete control over computers.
Recommendations For Firefox versions prior to 72.0.1, update to version 72.0.1 or later. For Firefox ESR versions prior to 68.4.1, update to version 68.4.1 or later. For Thunderbird versions prior to 68.4.1, update to version 68.4.1 or later. As a temporary workaround, consider restricting access to potentially vulnerable web pages until the update is applied.

Exploit

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2020-1110
ALT-PU-2020-1166
ALT-PU-2020-1515
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-00174
CESA-2020_0085
CESA-2020_0086
CESA-2020_0111
CESA-2020_0120
CESA-2020_0123
CESA-2020_0127
CVE-2019-17026
DLA-2061-1
DLA-2071-1
DLA-2093-1
DSA-4600-1
DSA-4603-1
ELSA-2020-0085
ELSA-2020-0086
ELSA-2020-0111
ELSA-2020-0120
ELSA-2020-0123
ELSA-2020-0127
MGASA-2020-0027
MGASA-2020-0034
OPENSUSE-SU-2020:0060-1
OPENSUSE-SU-2020:0094-1
OPENSUSE-SU-2020_0060-1
OPENSUSE-SU-2020_0094-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:0085
RHSA-2020:0086
RHSA-2020:0111
RHSA-2020:0120
RHSA-2020:0123
RHSA-2020:0127
RHSA-2020:0292
RHSA-2020:0295
RHSA-2020_0085
RHSA-2020_0086
RHSA-2020_0111
RHSA-2020_0120
RHSA-2020_0123
RHSA-2020_0127
SUSE-SU-2020:0068-1
SUSE-SU-2020:0078-1
SUSE-SU-2020:0142-1
SUSE-SU-2020:14268-1
SUSE-SU-2020_0068-1
SUSE-SU-2020_0078-1
SUSE-SU-2020_14268-1
USN-4234-1
USN-4234-2
USN-4241-1
USN-4335-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu