CVE-2019-17015Out-of-bounds Write in Mozilla Firefox

CWE-787Out-of-bounds Write10 documents8 sources
Severity
8.8HIGHNVD
EPSS
0.9%
top 23.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateMay 24

Description

During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDmozilla/firefox< 72.0
CVEListV5mozilla/firefoxbefore 72
CVEListV5mozilla/firefox_esrbefore 68.4

🔴Vulnerability Details

3
GHSA
GHSA-6jgc-63f5-7hch: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cra2022-05-24
OSV
CVE-2019-17015: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cra2020-01-08
CVEList
CVE-2019-17015: During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cra2020-01-08

📋Vendor Advisories

5
Red Hat
Mozilla: Memory corruption in parent process during new content process initialization on Windows2020-01-07
Debian
CVE-2019-17015: firefox - During the initialization of a new content process, a pointer offset can be mani...2019
Mozilla
Mozilla Foundation Security Advisory 2020-01: CVE-2019-17015
Mozilla
Mozilla Foundation Security Advisory 2020-02: CVE-2019-17015
Mozilla
Mozilla Foundation Security Advisory 2020-04: CVE-2019-17015

💬Community

1
Bugzilla
CVE-2019-17015 Mozilla: Memory corruption in parent process during new content process initialization on Windows2020-01-07
CVE-2019-17015 — Out-of-bounds Write in Mozilla Firefox | cvebase