CVE-2019-11760: Buffer Overflow
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances.
Other sources
A flaw was discovered in Mozilla Firefox and Thunderbird where a fixed-stack buffer overflow could occur during WebRTC signalling. The vulnerability could lead to an exploitable crash or leak data.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-11760.
What software versions are affected by this vulnerability?
This vulnerability affects Firefox versions prior to 70, Thunderbird versions prior to 68.2, and Firefox ESR versions prior to 68.2.
How severe is CVE-2019-11760?
CVE-2019-11760 has a severity rating of 8.8 (high).
What is the description of this vulnerability?
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling, leading to a potentially exploitable crash.
How do I fix CVE-2019-11760?
To fix CVE-2019-11760, update your Firefox to version 70 or later, Thunderbird to version 68.2 or later, or Firefox ESR to version 68.2 or later.