KLA11416
Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
Updated: 05/22/2020
Detect date
?
02/12/2019
Severity
?
High
Description

Multiple serious vulnerabilities were found in Mozilla Firefox and Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An use-after-free vulnerability in Skia can be exploited remotely via specially crafted website to execute arbitrary code;
  2. An integer overflow vulnerability in Skia can be exploited remotely via specially crafted website to cause denial of service;
  3. A cross-origin theft of images issue in ImageBitmapRenderingContext can be exploited to bypass security restrictions
  4. A buffer overflow vulnerability in Skia can be exploited remotely via specially crafted website to cause denial of service;

Technical details

Vulnerability (3) only affects Firefox 65.

Vulnerability (4) only affects Firefox ESR on macOS

Affected products

Mozilla Firefox earlier than 65.0.1
Mozilla Firefox ESR earlier than 60.5.1

Solution

Update to the latest version
Download Mozilla Firefox

Original advisories

Mozilla Foundation Security Advisory 2019-04
Mozilla Foundation Security Advisory 2019-05

Impacts
?
OSI 
[?]

DoS 
[?]
Related products
Mozilla Firefox
Mozilla Firefox ESR
CVE-IDS
?
CVE-2018-183350.0Unknown
CVE-2018-183560.0Unknown
CVE-2019-57850.0Unknown
CVE-2018-185110.0Unknown