CVE-2019-11693
published 2019-07-23CVE-2019-11693: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a…
critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 67.0-2 (sid) | firefox 67.0-2 (sid) |
| debian | firefox-esr | < firefox 67.0-2 (sid) | firefox 67.0-2 (sid) |
| debian | thunderbird | < firefox 67.0-2 (sid) | firefox 67.0-2 (sid) |
| mozilla | firefox | < 60.7.0 | 60.7.0 |
| mozilla | firefox | < 67.0 | 67.0 |
| mozilla | firefox | >= 0 < 67.0+build2-0ubuntu0.16.04.1 | 67.0+build2-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 67.0.2+build2-0ubuntu0.16.04.1 | 67.0.2+build2-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 67.0.1+build1-0ubuntu0.16.04.1 | 67.0.1+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 67.0+build2-0ubuntu0.18.04.1 | 67.0+build2-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 67.0.2+build2-0ubuntu0.18.04.1 | 67.0.2+build2-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 67.0.1+build1-0ubuntu0.18.04.1 | 67.0.1+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= unspecified < 67 | 67 |
| mozilla | firefox_esr | >= unspecified < 60.7 | 60.7 |
| mozilla | thunderbird | < 60.7.0 | 60.7.0 |
| mozilla | thunderbird | >= 0 < 1:60.7.0-1 | 1:60.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.7.0-1 | 1:60.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.7.0-1 | 1:60.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.7.0-1 | 1:60.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.7.0+build1-0ubuntu0.16.04.1 | 1:60.7.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.7.0+build1-0ubuntu0.18.04.1 | 1:60.7.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 60.7 | 60.7 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
Ubuntu
Firefox regression
vendor_ubuntu·2019-06-14·CVSS 9.8
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-3991-2 caused a regression in Firefox
USN-3991-1 fixed vulnerabilities in Firefox, and USN-3991-2 fixed a
subsequent regression. The update caused an additional regression that
resulted in Firefox failing to load correctly after executing it in safe
mode. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the browser
UI, trick the user in to launching local executable binaries, obtain
sensitive information, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11691, CVE-2019-11692,
Ubuntu
Firefox regression
vendor_ubuntu·2019-06-06·CVSS 9.8
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-3991-1 caused a regression in Firefox.
USN-3991-1 fixed vulnerabilities in Firefox. The update caused a
regression which resulted in issues when upgrading between Ubuntu
releases. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the browser
UI, trick the user in to launching local executable binaries, obtain
sensitive information, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-11695, CVE-2019-11696, CVE-2019-11699, CVE-2019-11
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-05-28·CVSS 9.8
CVE-2018-18511 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass same-origin protections, or execute arbitrary code.
(CVE-2019-18511, CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-9797, CVE-2019-9800, CVE-2019-9817, CVE-2019-9819, CVE-2019-9820)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2019-5798, CVE-2019-7317)
A type confusion bug was dis
Red Hat
Mozilla: Buffer overflow in WebGL bufferdata on Linux
vendor_redhat·2019-05-22·CVSS 9.8
CVE-2019-11693 [CRITICAL] CWE-120 Mozilla: Buffer overflow in WebGL bufferdata on Linux
Mozilla: Buffer overflow in WebGL bufferdata on Linux
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Statement: In general, this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail, but it is potentially a risk in browser or browser-like contexts.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2019-05-21·CVSS 9.8
CVE-2019-11691 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the browser
UI, trick the user in to launching local executable binaries, obtain
sensitive information, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-11695, CVE-2019-11696, CVE-2019-11699, CVE-2019-11701,
CVE-2019-7317, CVE-2019-9800, CVE-2019-9814, CVE-2019-9817, CVE-2019-9819,
CVE-2019-9820, CVE-2019-9821)
It was discovered that pressing certain key combinations could bypass
Red Hat
libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
vendor_redhat·2019-01-14·CVSS 8.1
CVE-2019-6286 [HIGH] CWE-125 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.
Package: libsass (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-11693: firefox - The bufferdata function in WebGL is vulnerable to a buffer overflow with specifi...
vendor_debian·2019·CVSS 9.8
CVE-2019-11693 [CRITICAL] CVE-2019-11693: firefox - The bufferdata function in WebGL is vulnerable to a buffer overflow with specifi...
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Scope: local
sid: resolved (fixed in 67.0-2)
GHSA
GHSA-rm3r-xfmr-5622: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux
ghsa_unreviewed·2022-05-24
CVE-2019-11693 [CRITICAL] CWE-119 GHSA-rm3r-xfmr-5622: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
OSV
CVE-2019-11693: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux
osv·2019-07-23·CVSS 9.8
CVE-2019-11693 [CRITICAL] CVE-2019-11693: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
OSV
firefox regression
osv·2019-06-14·CVSS 9.8
[CRITICAL] firefox regression
firefox regression
USN-3991-1 fixed vulnerabilities in Firefox, and USN-3991-2 fixed a
subsequent regression. The update caused an additional regression that
resulted in Firefox failing to load correctly after executing it in safe
mode. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the browser
UI, trick the user in to launching local executable binaries, obtain
sensitive information, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-11695, CVE-2019-11696, CVE-2019-1
OSV
firefox regression
osv·2019-06-06·CVSS 9.8
[CRITICAL] firefox regression
firefox regression
USN-3991-1 fixed vulnerabilities in Firefox. The update caused a
regression which resulted in issues when upgrading between Ubuntu
releases. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the browser
UI, trick the user in to launching local executable binaries, obtain
sensitive information, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-11695, CVE-2019-11696, CVE-2019-11699, CVE-2019-11701,
CVE-2019-7317, CVE-2019-9800, CVE-2019-9814, CVE-2019-9
OSV
thunderbird vulnerabilities
osv·2019-05-28·CVSS 9.8
CVE-2019-18511 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass same-origin protections, or execute arbitrary code.
(CVE-2019-18511, CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-9797, CVE-2019-9800, CVE-2019-9817, CVE-2019-9819, CVE-2019-9820)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2019-5798, CVE-2019-7317)
A type confusion bug was discovered with object groups and UnboxedObjects.
If a user were tricke
OSV
firefox vulnerabilities
osv·2019-05-21·CVSS 9.8
CVE-2019-11691 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the browser
UI, trick the user in to launching local executable binaries, obtain
sensitive information, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11691, CVE-2019-11692, CVE-2019-11693,
CVE-2019-11695, CVE-2019-11696, CVE-2019-11699, CVE-2019-11701,
CVE-2019-7317, CVE-2019-9800, CVE-2019-9814, CVE-2019-9817, CVE-2019-9819,
CVE-2019-9820, CVE-2019-9821)
It was discovered that pressing certain key combinations could bypass
addon installation prompt delays. If a user opened a specially crafted
website, an attacker could potentially ex
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11693 Mozilla: Buffer overflow in WebGL bufferdata on Linux
bugzilla·2019-05-22·CVSS 9.8
CVE-2019-11693 [CRITICAL] CVE-2019-11693 Mozilla: Buffer overflow in WebGL bufferdata on Linux
CVE-2019-11693 Mozilla: Buffer overflow in WebGL bufferdata on Linux
The `bufferdata` function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash.
*Note: this issue only occurs on Linux. Other operating systems are unaffected.*
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/#CVE-2019-11693
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: crixer
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:1265 https://access.redhat.com/errata/RHSA-2019:1265
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-
Bugzilla
CVE-2019-6286 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
bugzilla·2019-01-23·CVSS 8.1
CVE-2019-6286 [HIGH] CVE-2019-6286 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
CVE-2019-6286 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.
References:
https://github.com/sass/libsass/issues/2815
Discussion:
Created libsass tracking bugs for this issue:
Affects: epel-7 [bug 1668926]
Affects: fedora-all [bug 1668925]
https://bugzilla.mozilla.org/show_bug.cgi?id=1532525https://www.mozilla.org/security/advisories/mfsa2019-13/https://www.mozilla.org/security/advisories/mfsa2019-14/https://www.mozilla.org/security/advisories/mfsa2019-15/https://bugzilla.mozilla.org/show_bug.cgi?id=1532525https://www.mozilla.org/security/advisories/mfsa2019-13/https://www.mozilla.org/security/advisories/mfsa2019-14/https://www.mozilla.org/security/advisories/mfsa2019-15/
2019-07-23
Published