CVE-2019-11752: Use After Free
It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-11739
- CVE-2019-11746
- CVE-2019-11744
- CVE-2019-11742
- CVE-2019-11752
- CVE-2019-11743
- CVE-2019-11740
- CVE-2019-11751
- CVE-2019-11736
- CVE-2019-11753
- CVE-2019-9812
- CVE-2019-11748
- CVE-2019-11749
- CVE-2019-11750
- CVE-2019-11738
- CVE-2019-11747
- CVE-2019-11735
- CVE-2019-11741
- CVE-2019-5849
- CVE-2019-11737
- CVE-2019-11734
- CVE-2019-11758
Frequently Asked Questions
What is CVE-2019-11752?
CVE-2019-11752 is a vulnerability that allows an attacker to delete an IndexedDB key value and subsequently try to extract it during conversion, resulting in a use-after-free and a potentially exploitable crash.
Which software versions are affected by CVE-2019-11752?
Mozilla Firefox ESR versions up to 68.1, Mozilla Firefox versions up to 69, Mozilla Thunderbird versions up to 60.9.
What is the severity of CVE-2019-11752?
CVE-2019-11752 has a severity rating of 7 (high).
How can I fix CVE-2019-11752?
Update to Mozilla Firefox ESR version 68.1, Mozilla Firefox version 69, or Mozilla Thunderbird version 60.9.
Where can I find more information about CVE-2019-11752?
You can find more information about CVE-2019-11752 on the Mozilla Bugzilla page (https://bugzilla.mozilla.org/show_bug.cgi?id=1501152) and the Mozilla security advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/ and https://www.mozilla.org/en-US/security/advisories/mfsa2019-29/).