CVE-2019-17021
published 2020-01-08CVE-2019-17021: During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent…
PriorityP425medium5.3CVSS 3.1
AVNACHPRNUIRSUCHINAN
EPSS
1.87%
77.2th percentile
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 72.0 | 72.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 68.4 | 68.4 |
| mozilla | firefox_esr | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Heap address disclosure in parent process during content process initialization on Windows
vendor_redhat·2020-01-07·CVSS 5.3
CVE-2019-17021 [MEDIUM] CWE-362 Mozilla: Heap address disclosure in parent process during content process initialization on Windows
Mozilla: Heap address disclosure in parent process during content process initialization on Windows
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Packa
Debian
CVE-2019-17021: firefox - During the initialization of a new content process, a race condition occurs that...
vendor_debian·2019·CVSS 5.3
CVE-2019-17021 [MEDIUM] CVE-2019-17021: firefox - During the initialization of a new content process, a race condition occurs that...
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-04: CVE-2019-17021
vendor_mozilla·CVSS 5.3
CVE-2019-17021 [MEDIUM] Mozilla Foundation Security Advisory 2020-04: CVE-2019-17021
Mozilla Foundation Security Advisory 2020-04
CVE: CVE-2019-17021
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 68.4.1
Mozilla
Mozilla Foundation Security Advisory 2020-02: CVE-2019-17021
vendor_mozilla·CVSS 5.3
CVE-2019-17021 [MEDIUM] Mozilla Foundation Security Advisory 2020-02: CVE-2019-17021
Mozilla Foundation Security Advisory 2020-02
CVE: CVE-2019-17021
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.4
Mozilla
Mozilla Foundation Security Advisory 2020-01: CVE-2019-17021
vendor_mozilla·CVSS 5.3
CVE-2019-17021 [MEDIUM] Mozilla Foundation Security Advisory 2020-01: CVE-2019-17021
Mozilla Foundation Security Advisory 2020-01
CVE: CVE-2019-17021
Product: Firefox
Impact: high
Fixed in: Firefox 72
GHSA
GHSA-23vm-fc59-7qjv: During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the paren
ghsa_unreviewed·2022-05-24
CVE-2019-17021 [LOW] CWE-200 GHSA-23vm-fc59-7qjv: During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the paren
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
OSV
CVE-2019-17021: During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the paren
osv·2020-01-08·CVSS 5.3
CVE-2019-17021 [MEDIUM] CVE-2019-17021: During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the paren
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00043.htmlhttp://packetstormsecurity.com/files/155912/Slackware-Security-Advisory-mozilla-thunderbird-Updates.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1599008https://seclists.org/bugtraq/2020/Jan/18https://www.mozilla.org/security/advisories/mfsa2020-01/https://www.mozilla.org/security/advisories/mfsa2020-02/http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00043.htmlhttp://packetstormsecurity.com/files/155912/Slackware-Security-Advisory-mozilla-thunderbird-Updates.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1599008https://seclists.org/bugtraq/2020/Jan/18https://www.mozilla.org/security/advisories/mfsa2020-01/https://www.mozilla.org/security/advisories/mfsa2020-02/
2020-01-08
Published