CVE-2019-11709: Critical severity thunderbird vulnerability
Mozilla developers and community members Andreea Pavel, Christian Holler, Honza Bambas, Jason Kratzer, and Jeff Gilbert reported memory safety bugs fixed in Firefox 68, Firefox ESR 60.8, and Thunderbird 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Other sources
Mozilla developers and community members Andreea Pavel, Christian Holler, Honza Bambas, Jason Kratzer, and Jeff Gilbert reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Mozilla developers and community members Andreea Pavel, Christian Holler, Honza Bambas, Jason Kratzer, and Jeff Gilbert reported memory safety bugs present in Firefox 67, Firefox ESR 60.7, and Thunderbird 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11709?
CVE-2019-11709 is a vulnerability related to memory safety bugs present in Firefox 67, Firefox ESR 60.7, and Thunderbird 60.7.
What is the severity of CVE-2019-11709?
The severity of CVE-2019-11709 is critical with a severity value of 9.
How do I fix CVE-2019-11709?
To fix CVE-2019-11709, update to Mozilla Firefox version 68 or Mozilla Firefox ESR version 60.8.
Where can I find more information about CVE-2019-11709?
You can find more information about CVE-2019-11709 on the Mozilla bugzilla page and the Mozilla security advisories page.
What is the CWE ID for CVE-2019-11709?
The CWE ID for CVE-2019-11709 is 787.