Bug 1764446 (CVE-2019-11764) - CVE-2019-11764 Mozilla: Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2
Summary: CVE-2019-11764 Mozilla: Memory safety bugs fixed in Firefox 70 and Firefox ES...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-11764
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1763562 1764938 1763558 1763559 1763560 1763561 1763563 1764206 1764937 1764939 1764940 1764941 1764942
Blocks: 1763556
TreeView+ depends on / blocked
 
Reported: 2019-10-23 05:41 UTC by Doran Moppert
Modified: 2019-12-02 18:22 UTC (History)
6 users (show)

Fixed In Version: firefox 68.2, thunderbird 68.2
Doc Type: If docs needed, set a value
Doc Text:
Several memory safety bugs were discovered in Mozilla Firefox and Thunderbird. Memory corruption and arbitrary code execution are possible with these vulnerabilities. These bugs can be exploited over the network.
Clone Of:
Environment:
Last Closed: 2019-10-25 00:51:45 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:3193 None None None 2019-10-23 14:00:52 UTC
Red Hat Product Errata RHSA-2019:3196 None None None 2019-10-24 08:24:51 UTC
Red Hat Product Errata RHSA-2019:3210 None None None 2019-10-29 09:49:15 UTC
Red Hat Product Errata RHSA-2019:3237 None None None 2019-10-29 13:47:07 UTC
Red Hat Product Errata RHSA-2019:3281 None None None 2019-10-31 14:08:24 UTC
Red Hat Product Errata RHSA-2019:3756 None None None 2019-11-06 17:08:44 UTC

Description Doran Moppert 2019-10-23 05:41:37 UTC
Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code.


External Reference:

https://www.mozilla.org/en-US/security/advisories/mfsa2019-33/#CVE-2019-11764

Comment 1 Doran Moppert 2019-10-23 05:41:40 UTC
Acknowledgments:

Name: the Mozilla project
Upstream: Bob Clary, Jason Kratzer, Aaron Klotz, Iain Ireland, Tyson Smith, Christian Holler, Steve Fink, Honza Bambas, Byron Campen, Cristian Brindusan

Comment 2 errata-xmlrpc 2019-10-23 14:00:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:3193 https://access.redhat.com/errata/RHSA-2019:3193

Comment 3 errata-xmlrpc 2019-10-24 08:24:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:3196 https://access.redhat.com/errata/RHSA-2019:3196

Comment 4 Product Security DevOps Team 2019-10-25 00:51:45 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-11764

Comment 5 errata-xmlrpc 2019-10-29 09:49:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:3210 https://access.redhat.com/errata/RHSA-2019:3210

Comment 6 errata-xmlrpc 2019-10-29 13:47:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:3237 https://access.redhat.com/errata/RHSA-2019:3237

Comment 7 errata-xmlrpc 2019-10-31 14:08:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:3281 https://access.redhat.com/errata/RHSA-2019:3281

Comment 8 errata-xmlrpc 2019-11-06 17:08:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:3756 https://access.redhat.com/errata/RHSA-2019:3756


Note You need to log in before you can comment on or make changes to this bug.