CVE-2019-11742: Medium severity Mozilla Thunderbird vulnerability
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Other sources
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-11739
- CVE-2019-11746
- CVE-2019-11744
- CVE-2019-11742
- CVE-2019-11752
- CVE-2019-11743
- CVE-2019-11740
- CVE-2019-11751
- CVE-2019-11736
- CVE-2019-11753
- CVE-2019-9812
- CVE-2019-11748
- CVE-2019-11749
- CVE-2019-11750
- CVE-2019-11738
- CVE-2019-11747
- CVE-2019-11735
- CVE-2019-11741
- CVE-2019-5849
- CVE-2019-11737
- CVE-2019-11734
- CVE-2019-11758
Frequently Asked Questions
What is CVE-2019-11742?
CVE-2019-11742 is a vulnerability that allows for the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content.
How does CVE-2019-11742 work?
CVE-2019-11742 works by exploiting a same-origin policy violation that allows for the theft of cross-origin images using SVG filters and a <canvas> element.
Which software products are affected by CVE-2019-11742?
Mozilla Firefox ESR versions up to 68.1, Mozilla Firefox versions up to 69, Mozilla Thunderbird versions up to 60.9, and Mozilla Firefox ESR versions up to 68.1 are affected by CVE-2019-11742.
What is the severity of CVE-2019-11742?
CVE-2019-11742 has a severity rating of high with a value of 7.
How can CVE-2019-11742 be fixed?
To fix CVE-2019-11742, update Mozilla Firefox ESR to version 68.1 or later, update Mozilla Firefox to version 69 or later, update Mozilla Thunderbird to version 60.9 or later, or update Mozilla Firefox ESR to version 68.1 or later.