Bug 1764444 (CVE-2019-11763)
Summary: | CVE-2019-11763 Mozilla: Incorrect HTML parsing results in XSS bypass technique | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Doran Moppert <dmoppert> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | cschalle, gecko-bugs-nobody, jhorak, security-response-team, stransky |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | firefox 68.2, thunderbird 68.2 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in Mozilla Firefox and Thunderbird where null bytes were incorrectly parsed in HTML entities. This could lead to HTML comments being treated as code which could lead to XSS in a web application or HTML entities being masked from filters.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-10-25 00:51:42 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1763558, 1763559, 1763560, 1763561, 1763562, 1763563, 1764206, 1764937, 1764938, 1764939, 1764940, 1764941, 1764942 | ||
Bug Blocks: | 1763556 |
Description
Doran Moppert
2019-10-23 05:40:35 UTC
Acknowledgments: Name: the Mozilla project Upstream: Gareth Heyes This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:3193 https://access.redhat.com/errata/RHSA-2019:3193 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:3196 https://access.redhat.com/errata/RHSA-2019:3196 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11763 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:3210 https://access.redhat.com/errata/RHSA-2019:3210 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:3237 https://access.redhat.com/errata/RHSA-2019:3237 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2019:3281 https://access.redhat.com/errata/RHSA-2019:3281 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2019:3756 https://access.redhat.com/errata/RHSA-2019:3756 |