Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade firefox-esr | Aug 22, 2024 | Jan 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Apr 27, 2020 | Jan 8, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 8, 2020 |
| Centos_linux | — | Upgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird-debugsourceUpgrade thunderbird | Dec 6, 2019 | Dec 5, 2019 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Dec 12, 2019 | Dec 12, 2019 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird. | Mar 13, 2020 | Jan 8, 2020 |
| Mfsa2019 36 | — | Upgrade to Mozilla Firefox version 71.0 | Dec 4, 2019 | Dec 3, 2019 |
| Mfsa2019 37 | — | Upgrade to Mozilla Firefox ESR version 68.3 | Dec 4, 2019 | Dec 3, 2019 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.3 | Dec 5, 2019 | Dec 3, 2019 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 68.3.0-11.4.17.0.1.2.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.3.0-11.4.17.0.1.2.0 on Solaris 11.4Upgrade mail/thunderbird to version 68.3.0-11.4.17.0.1.2.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.3.0-11.4.17.0.1.2.0 on Solaris 11.4 | Jan 19, 2021 | Jan 8, 2020 |
| Oracle_linux | — | Upgrade firefoxUpgrade thunderbird | Dec 12, 2019 | Dec 3, 2019 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade firefoxNo solution existsUpgrade firefox-debugsource | Dec 6, 2019 | Dec 5, 2019 |
| Suse | — | Upgrade mozilla-nss-develUpgrade libsoftokn3Upgrade mozillafirefox-translations-otherUpgrade mozillafirefox-develUpgrade mozilla-nsprUpgrade mozilla-nspr-develUpgrade mozilla-nspr-32bitUpgrade libsoftokn3-32bitUpgrade libfreebl3Upgrade mozillathunderbird-translations-commonUpgrade mozilla-nss-toolsUpgrade mozillafirefox-translations-commonUpgrade mozilla-nssUpgrade mozilla-nss-32bitUpgrade mozillathunderbird-translations-otherUpgrade mozillafirefox-buildsymbolsUpgrade mozilla-nss-certsUpgrade mozillafirefoxUpgrade libfreebl3-32bitUpgrade mozillathunderbirdUpgrade mozilla-nss-certs-32bitUpgrade mozillafirefox-branding-upstream | Dec 20, 2019 | Dec 9, 2019 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Dec 10, 2019 | Dec 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub