CVE-2019-9811

CWE-74CWE-80713 documents8 sources
Severity
8.3HIGH
EPSS
0.7%
top 28.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages12 packages

CVEListV5mozilla/firefoxunspecified68
NVDmozilla/firefox< 68.0
CVEListV5mozilla/firefox_esrunspecified60.8
Ubuntufirefox< 68.0+build3-0ubuntu0.16.04.1+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

6
GHSA
GHSA-63j5-535g-4392: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feat2022-05-24
OSV
firefox regressions2019-07-25
CVEList
CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feat2019-07-23
OSV
CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feat2019-07-23
OSV
thunderbird vulnerabilities2019-07-17

📋Vendor Advisories

5
Ubuntu
Firefox regressions2019-07-25
Ubuntu
Thunderbird vulnerabilities2019-07-17
Ubuntu
Firefox vulnerabilities2019-07-12
Red Hat
Mozilla: Sandbox escape via installation of malicious language pack2019-07-10
Debian
CVE-2019-9811: firefox - As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape b...2019

💬Community

1
Bugzilla
CVE-2019-9811 Mozilla: Sandbox escape via installation of malicious language pack2019-07-10
CVE-2019-9811 (HIGH CVSS 8.3) | As part of a winning Pwn2Own entry | cvebase.io