CVE-2019-11752Use After Free in Mozilla Firefox

CWE-416Use After Free15 documents9 sources
Severity
8.8HIGHNVD
OSV9.8OSV6.5
EPSS
0.9%
top 24.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateMay 24

Description

It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified69
NVDmozilla/firefox< 60.9.0+1
CVEListV5mozilla/firefox_esrunspecified60.9+1
NVDmozilla/firefox_esr68.068.1.0
Ubuntumozilla/firefox< 69.0+build2-0ubuntu0.16.04.4+3

🔴Vulnerability Details

6
GHSA
GHSA-5xqq-gc4j-mg29: It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion2022-05-24
OSV
thunderbird vulnerabilities2019-10-08
OSV
firefox regression2019-10-08
CVEList
CVE-2019-11752: It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion2019-09-27
OSV
CVE-2019-11752: It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion2019-09-27

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2019-10-08
Ubuntu
Firefox regression2019-10-08
Ubuntu
Firefox vulnerabilities2019-09-04
Red Hat
Mozilla: Use-after-free while extracting a key value in IndexedDB2019-09-03
Debian
CVE-2019-11752: firefox - It is possible to delete an IndexedDB key value and subsequently try to extract ...2019

📄Research Papers

1
arXiv
xTag: Mitigating Use-After-Free Vulnerabilities via Software-Based Pointer Tagging on Intel x86-642022-03-08

💬Community

2
Bugzilla
CVE-2019-11752 Mozilla: Use-after-free while extracting a key value in IndexedDB2019-09-04
Bugzilla
Firefox 69.0 is available2019-09-03
CVE-2019-11752 — Use After Free in Mozilla Firefox | cvebase