Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esrUpgrade firefox | Aug 22, 2024 | Jan 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Apr 27, 2020 | Jan 8, 2020 |
| Centos_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade thunderbird-debugsource | Oct 25, 2019 | Oct 23, 2019 |
| Mfsa2019 25 | — | Upgrade to Mozilla Firefox version 69.0 | Oct 23, 2019 | Sep 3, 2019 |
| Mfsa2019 33 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 68.2 | Oct 23, 2019 | Oct 22, 2019 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.2Upgrade to the latest version of Mozilla Thunderbird | Oct 25, 2019 | Oct 22, 2019 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4Upgrade mail/thunderbird to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.2.0-11.4.15.0.1.4.0 on Solaris 11.4 | Nov 20, 2019 | Nov 20, 2019 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Oct 30, 2019 | Oct 22, 2019 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoUpgrade firefox-debugsourceUpgrade firefoxUpgrade firefox-debuginfoNo solution existsUpgrade thunderbirdUpgrade thunderbird-debugsource | Oct 25, 2019 | Oct 23, 2019 |
| Suse | — | Upgrade firefox-gtk3-toolsUpgrade MozillaFirefox-branding-SLEDUpgrade mozilla-nss-certsUpgrade MozillaFirefox-branding-openSUSEUpgrade MozillaThunderbird-translations-otherUpgrade firefox-gtk3-immodules-tigrignaUpgrade libfreebl3Upgrade firefox-glib2-langUpgrade libfreebl3-32bitUpgrade mozilla-nss-32bitUpgrade MozillaFirefox-translations-otherUpgrade firefox-glib2-toolsUpgrade firefox-libgdk_pixbuf-2_0-0Upgrade mozilla-nspr-32bitUpgrade mozilla-nssUpgrade mozilla-nss-develUpgrade firefox-gtk3-immodule-inuktitutUpgrade firefox-gtk3-immodule-multipressUpgrade mozilla-nss-toolsUpgrade mozillafirefox-branding-sleUpgrade libsoftokn3Upgrade firefox-libharfbuzz0Upgrade firefox-gtk3-immodule-thaiUpgrade mozilla-nss-certs-32bitUpgrade mozilla-nsprUpgrade firefox-gtk3-branding-upstreamUpgrade libfirefox-gmodule-2_0-0Upgrade firefox-esr-branding-openSUSEUpgrade firefox-libpango-1_0-0Upgrade mozillafirefox-branding-upstreamUpgrade firefox-libgtk-3-0Upgrade firefox-gtk3-dataUpgrade MozillaThunderbirdUpgrade firefox-libffi7Upgrade MozillaFirefox-develUpgrade libfirefox-gio-2_0-0Upgrade firefox-gio-branding-upstreamUpgrade libfirefox-gobject-2_0-0Upgrade firefox-libffi4Upgrade firefox-gtk3-immodule-amharicUpgrade firefox-libatk-1_0-0Upgrade mozilla-nspr-develUpgrade libsoftokn3-32bitUpgrade firefox-libcairo-gobject2Upgrade firefox-gtk3-immodule-vietnameseUpgrade firefox-atk-langUpgrade firefox-gdk-pixbuf-query-loadersUpgrade firefox-libcairo2Upgrade MozillaFirefoxUpgrade mozillafirefox-buildsymbolsUpgrade MozillaFirefox-translations-commonUpgrade firefox-gdk-pixbuf-thumbnailerUpgrade libfirefox-gthread-2_0-0Upgrade libfirefox-glib-2_0-0Upgrade firefox-gdk-pixbuf-langUpgrade firefox-gtk3-langUpgrade firefox-gtk3-immodule-ximUpgrade MozillaThunderbird-translations-common | Nov 1, 2019 | Oct 29, 2019 |
| Ubuntu | — | Upgrade thunderbird | Nov 27, 2019 | Oct 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub