When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade librewolfUpgrade firefox-esrUpgrade firefox | Aug 22, 2024 | Jan 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Apr 27, 2020 | Jan 8, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 8, 2020 |
| Centos_linux | — | Upgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade thunderbirdUpgrade firefox | Oct 25, 2019 | Oct 23, 2019 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Oct 28, 2019 | Oct 28, 2019 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Mar 16, 2020 | Jan 8, 2020 |
| Mfsa2019 33 | — | Upgrade to Mozilla Firefox ESR version 68.2 | Oct 23, 2019 | Oct 22, 2019 |
| Mfsa2019 34 | — | Upgrade to Mozilla Firefox version 70.0 | Oct 23, 2019 | Oct 22, 2019 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.2 | Oct 25, 2019 | Oct 22, 2019 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4Upgrade mail/thunderbird to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4Upgrade web/browser/firefox to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4 | Nov 20, 2019 | Nov 20, 2019 |
| Oracle_linux | — | Upgrade firefoxUpgrade thunderbird | Oct 30, 2019 | Oct 22, 2019 |
| Redhat_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade firefoxUpgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade thunderbird-debuginfoNo solution exists | Oct 25, 2019 | Oct 23, 2019 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-otherUpgrade firefox-libharfbuzz0Upgrade firefox-gtk3-immodule-multipressUpgrade MozillaFirefox-translations-commonUpgrade mozilla-nspr-32bitUpgrade firefox-libcairo-gobject2Upgrade firefox-gtk3-branding-upstreamUpgrade mozilla-nssUpgrade mozilla-nspr-develUpgrade firefox-glib2-langUpgrade firefox-gtk3-toolsUpgrade firefox-libffi7Upgrade firefox-libffi4Upgrade firefox-gtk3-immodule-thaiUpgrade firefox-gio-branding-upstreamUpgrade libsoftokn3-32bitUpgrade libfirefox-gthread-2_0-0Upgrade firefox-gtk3-immodule-ximUpgrade MozillaFirefox-branding-SLEDUpgrade MozillaThunderbirdUpgrade MozillaFirefox-branding-openSUSEUpgrade firefox-gtk3-immodules-tigrignaUpgrade firefox-libgtk-3-0Upgrade firefox-gdk-pixbuf-query-loadersUpgrade firefox-gtk3-dataUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade firefox-atk-langUpgrade mozillafirefox-branding-upstreamUpgrade libfirefox-gmodule-2_0-0Upgrade firefox-libatk-1_0-0Upgrade mozilla-nss-toolsUpgrade firefox-glib2-toolsUpgrade firefox-gtk3-immodule-inuktitutUpgrade firefox-libpango-1_0-0Upgrade libfirefox-gio-2_0-0Upgrade firefox-gtk3-langUpgrade mozilla-nss-develUpgrade mozilla-nsprUpgrade libfirefox-gobject-2_0-0Upgrade firefox-esr-branding-openSUSEUpgrade mozillafirefox-branding-sleUpgrade libfirefox-glib-2_0-0Upgrade libfreebl3Upgrade firefox-libcairo2Upgrade libsoftokn3Upgrade libfreebl3-32bitUpgrade firefox-libgdk_pixbuf-2_0-0Upgrade firefox-gtk3-immodule-vietnameseUpgrade mozilla-nss-certs-32bitUpgrade firefox-gdk-pixbuf-thumbnailerUpgrade MozillaFirefoxUpgrade firefox-gdk-pixbuf-langUpgrade firefox-gtk3-immodule-amharicUpgrade mozillafirefox-buildsymbolsUpgrade mozilla-nss-certsUpgrade mozilla-nss-32bit | Nov 1, 2019 | Oct 23, 2019 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Oct 24, 2019 | Oct 23, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub