CVE-2019-9818Race Condition in Mozilla Firefox

Severity
8.3HIGHNVD
EPSS
0.3%
top 43.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified67
NVDmozilla/firefox< 67.0
CVEListV5mozilla/firefox_esrunspecified60.7

🔴Vulnerability Details

2
GHSA
GHSA-r9p3-38m2-qxq8: A race condition is present in the crash generation server used to generate data for the crash reporter2022-05-24
OSV
CVE-2019-9818: A race condition is present in the crash generation server used to generate data for the crash reporter2019-07-23

📋Vendor Advisories

2
Red Hat
Mozilla: Use-after-free in crash generation server2019-05-22
Debian
CVE-2019-9818: firefox - A race condition is present in the crash generation server used to generate data...2019

💬Community

1
Bugzilla
CVE-2019-9818 Mozilla: Use-after-free in crash generation server2019-05-22