CVE-2019-17015
published 2020-01-08CVE-2019-17015: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the…
PriorityP339high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.81%
76.2th percentile
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 72.0 | 72.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 68.4 | 68.4 |
| mozilla | firefox_esr | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Memory corruption in parent process during new content process initialization on Windows
vendor_redhat·2020-01-07·CVSS 8.8
CVE-2019-17015 [HIGH] CWE-787 Mozilla: Memory corruption in parent process during new content process initialization on Windows
Mozilla: Memory corruption in parent process during new content process initialization on Windows
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not af
Debian
CVE-2019-17015: firefox - During the initialization of a new content process, a pointer offset can be mani...
vendor_debian·2019·CVSS 8.8
CVE-2019-17015 [HIGH] CVE-2019-17015: firefox - During the initialization of a new content process, a pointer offset can be mani...
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-01: CVE-2019-17015
vendor_mozilla·CVSS 8.8
CVE-2019-17015 [HIGH] Mozilla Foundation Security Advisory 2020-01: CVE-2019-17015
Mozilla Foundation Security Advisory 2020-01
CVE: CVE-2019-17015
Product: Firefox
Impact: high
Fixed in: Firefox 72
Mozilla
Mozilla Foundation Security Advisory 2020-02: CVE-2019-17015
vendor_mozilla·CVSS 8.8
CVE-2019-17015 [HIGH] Mozilla Foundation Security Advisory 2020-02: CVE-2019-17015
Mozilla Foundation Security Advisory 2020-02
CVE: CVE-2019-17015
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.4
Mozilla
Mozilla Foundation Security Advisory 2020-04: CVE-2019-17015
vendor_mozilla·CVSS 8.8
CVE-2019-17015 [HIGH] Mozilla Foundation Security Advisory 2020-04: CVE-2019-17015
Mozilla Foundation Security Advisory 2020-04
CVE: CVE-2019-17015
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 68.4.1
GHSA
GHSA-6jgc-63f5-7hch: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cra
ghsa_unreviewed·2022-05-24
CVE-2019-17015 [MEDIUM] GHSA-6jgc-63f5-7hch: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cra
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
OSV
CVE-2019-17015: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cra
osv·2020-01-08·CVSS 8.8
CVE-2019-17015 [HIGH] CVE-2019-17015: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cra
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00043.htmlhttp://packetstormsecurity.com/files/155912/Slackware-Security-Advisory-mozilla-thunderbird-Updates.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1599005https://seclists.org/bugtraq/2020/Jan/18https://www.mozilla.org/security/advisories/mfsa2020-01/https://www.mozilla.org/security/advisories/mfsa2020-02/http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00043.htmlhttp://packetstormsecurity.com/files/155912/Slackware-Security-Advisory-mozilla-thunderbird-Updates.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1599005https://seclists.org/bugtraq/2020/Jan/18https://www.mozilla.org/security/advisories/mfsa2020-01/https://www.mozilla.org/security/advisories/mfsa2020-02/
2020-01-08
Published