CVE-2019-11759: Buffer Overflow
A flaw was discovered in both Firefox and Thunderbird where 4 bytes of a HMAC output could be written past the end of a buffer stored on the memory stack. This could allow an attacker to execute arbitrary code or lead to a crash. This flaw can be exploited over the network.
Other sources
An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11759?
CVE-2019-11759 is a vulnerability that could allow an attacker to execute arbitrary code or cause a crash by writing 4 bytes of HMAC output past the end of a buffer stored on the stack.
Which software versions are affected by CVE-2019-11759?
Firefox versions earlier than 70, Thunderbird versions earlier than 68.2, and Firefox ESR versions earlier than 68.2 are affected by CVE-2019-11759.
What is the severity of CVE-2019-11759?
CVE-2019-11759 has a high severity rating of 8.8.
How can this vulnerability be fixed?
To fix CVE-2019-11759, update Firefox to version 70 or later, Thunderbird to version 68.2 or later, and Firefox ESR to version 68.2 or later.
Where can I find more information about CVE-2019-11759?
More information about CVE-2019-11759 can be found in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1577953), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2019-33/), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2019-35/).