A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
https://bugzilla.mozilla.org/show_bug.cgi?id=1536405
https://www.mozilla.org/security/advisories/mfsa2019-13/
Source: MITRE
Published: 2019-07-23
Updated: 2019-07-26
Type: CWE-416
Base Score: 7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 10
Severity: HIGH
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 3.9
Severity: CRITICAL
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
145688 | CentOS 8 : firefox (CESA-2019:1269) | Nessus | CentOS Local Security Checks | high |
145630 | CentOS 8 : thunderbird (CESA-2019:1308) | Nessus | CentOS Local Security Checks | high |
128698 | NewStart CGSL MAIN 4.06 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0178) | Nessus | NewStart CGSL Local Security Checks | critical |
128691 | NewStart CGSL MAIN 4.06 : firefox Multiple Vulnerabilities (NS-SA-2019-0175) | Nessus | NewStart CGSL Local Security Checks | critical |
127589 | Oracle Linux 8 : thunderbird (ELSA-2019-1308) | Nessus | Oracle Linux Local Security Checks | high |
127587 | Oracle Linux 8 : firefox (ELSA-2019-1269) | Nessus | Oracle Linux Local Security Checks | high |
127459 | NewStart CGSL MAIN 4.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0169) | Nessus | NewStart CGSL Local Security Checks | high |
127455 | NewStart CGSL MAIN 4.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0167) | Nessus | NewStart CGSL Local Security Checks | high |
127439 | NewStart CGSL CORE 5.04 / MAIN 5.04 : firefox Multiple Vulnerabilities (NS-SA-2019-0159) | Nessus | NewStart CGSL Local Security Checks | high |
127438 | NewStart CGSL CORE 5.04 / MAIN 5.04 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0158) | Nessus | NewStart CGSL Local Security Checks | high |
127305 | NewStart CGSL CORE 5.05 / MAIN 5.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0088) | Nessus | NewStart CGSL Local Security Checks | high |
127304 | NewStart CGSL CORE 5.05 / MAIN 5.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0087) | Nessus | NewStart CGSL Local Security Checks | high |
125948 | Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : Firefox regression (USN-3991-3) | Nessus | Ubuntu Local Security Checks | high |
125901 | Amazon Linux 2 : thunderbird (ALAS-2019-1229) | Nessus | Amazon Linux Local Security Checks | high |
125809 | openSUSE Security Update : MozillaFirefox (openSUSE-2019-1534) | Nessus | SuSE Local Security Checks | high |
125803 | CentOS 6 : thunderbird (CESA-2019:1310) | Nessus | CentOS Local Security Checks | high |
125802 | CentOS 7 : thunderbird (CESA-2019:1309) | Nessus | CentOS Local Security Checks | high |
125766 | Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : firefox regression (USN-3991-2) | Nessus | Ubuntu Local Security Checks | high |
125716 | Scientific Linux Security Update : thunderbird on SL7.x x86_64 (20190604) | Nessus | Scientific Linux Local Security Checks | high |
125715 | Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20190604) | Nessus | Scientific Linux Local Security Checks | high |
125702 | SUSE SLED15 / SLES15 Security Update : MozillaFirefox (SUSE-SU-2019:1405-1) | Nessus | SuSE Local Security Checks | high |
125692 | RHEL 6 : thunderbird (RHSA-2019:1310) | Nessus | Red Hat Local Security Checks | high |
125691 | RHEL 7 : thunderbird (RHSA-2019:1309) | Nessus | Red Hat Local Security Checks | high |
125690 | RHEL 8 : thunderbird (RHSA-2019:1308) | Nessus | Red Hat Local Security Checks | high |
125689 | Oracle Linux 6 : thunderbird (ELSA-2019-1310) | Nessus | Oracle Linux Local Security Checks | high |
125688 | Oracle Linux 7 : thunderbird (ELSA-2019-1309) | Nessus | Oracle Linux Local Security Checks | high |
125672 | SUSE SLED12 / SLES12 Security Update : MozillaFirefox (SUSE-SU-2019:1388-1) | Nessus | SuSE Local Security Checks | high |
125669 | openSUSE Security Update : MozillaThunderbird (openSUSE-2019-1484) | Nessus | SuSE Local Security Checks | high |
125554 | CentOS 6 : firefox (CESA-2019:1267) | Nessus | CentOS Local Security Checks | high |
125553 | CentOS 7 : firefox (CESA-2019:1265) | Nessus | CentOS Local Security Checks | high |
125545 | Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : Thunderbird vulnerabilities (USN-3997-1) | Nessus | Ubuntu Local Security Checks | high |
125449 | Scientific Linux Security Update : firefox on SL7.x x86_64 (20190524) | Nessus | Scientific Linux Local Security Checks | high |
125447 | Scientific Linux Security Update : firefox on SL6.x i386/x86_64 (20190523) | Nessus | Scientific Linux Local Security Checks | high |
125444 | Oracle Linux 6 : firefox (ELSA-2019-1267) | Nessus | Oracle Linux Local Security Checks | high |
125443 | Oracle Linux 7 : firefox (ELSA-2019-1265) | Nessus | Oracle Linux Local Security Checks | high |
125415 | Debian DSA-4451-1 : thunderbird - security update | Nessus | Debian Local Security Checks | high |
125412 | Debian DLA-1806-1 : thunderbird security update | Nessus | Debian Local Security Checks | high |
125385 | RHEL 8 : firefox (RHSA-2019:1269) | Nessus | Red Hat Local Security Checks | high |
125383 | RHEL 6 : firefox (RHSA-2019:1267) | Nessus | Red Hat Local Security Checks | high |
125382 | RHEL 7 : firefox (RHSA-2019:1265) | Nessus | Red Hat Local Security Checks | high |
125374 | Debian DLA-1800-1 : firefox-esr security update | Nessus | Debian Local Security Checks | high |
125363 | Mozilla Firefox ESR < 60.7 | Nessus | Windows | high |
125362 | Mozilla Firefox ESR < 60.7 | Nessus | MacOS X Local Security Checks | high |
125361 | Mozilla Firefox < 67.0 | Nessus | Windows | high |
125360 | Mozilla Firefox < 67.0 | Nessus | MacOS X Local Security Checks | high |
125359 | Mozilla Thunderbird < 60.7 | Nessus | Windows | high |
125358 | Mozilla Thunderbird < 60.7 | Nessus | MacOS X Local Security Checks | high |
125346 | FreeBSD : mozilla -- multiple vulnerabilities (44b6dfbf-4ef7-4d52-ad52-2b1b05d81272) | Nessus | FreeBSD Local Security Checks | high |
125343 | Debian DSA-4448-1 : firefox-esr - security update | Nessus | Debian Local Security Checks | high |
125339 | Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : Firefox vulnerabilities (USN-3991-1) | Nessus | Ubuntu Local Security Checks | high |
700733 | Mozilla Firefox ESR < 60.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | critical |
700727 | Mozilla Firefox < 67.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | critical |
700742 | Mozilla Thunderbird < 60.7 Multiple Vulnerabilities | Nessus Network Monitor | SMTP Clients | high |