Vulnerability CVE-2019-17026: Information

Description

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: March 2, 2020
Modified: Nov. 16, 2022
Error type identifier: CWE-843

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus72.0.2-alt1125.0.2-alt1ALT-PU-2020-1110-1244791Fixed
firefoxp1072.0.2-alt1118.0.2-alt0.p10.1ALT-PU-2020-1110-1244791Fixed
firefoxp972.0.2-alt0.1.p9105.0.1-alt0.c9.1ALT-PU-2020-1617-1245893Fixed
firefoxc10f172.0.2-alt1112.0.2-alt0.p10.1ALT-PU-2020-1110-1244791Fixed
firefoxc9f272.0.2-alt0.1.p9105.0.1-alt0.c9.1ALT-PU-2020-1617-1245893Fixed
firefox-esrsisyphus78.0.2-alt1115.10.0-alt1ALT-PU-2020-2408-1255107Fixed
firefox-esrp1078.0.2-alt1115.10.0-alt1ALT-PU-2020-2408-1255107Fixed
firefox-esrp978.3.0-alt0.1.p9102.11.0-alt0.c9.1ALT-PU-2020-2933-1254920Fixed
firefox-esrc10f178.0.2-alt1115.9.1-alt0.c10.1ALT-PU-2020-2408-1255107Fixed
firefox-esrc9f278.7.1-alt0.1.c9102.12.0-alt0.c9.1ALT-PU-2021-1368-1264611Fixed
thunderbirdsisyphus68.4.2-alt1115.9.0-alt1ALT-PU-2020-1166-1243898Fixed
thunderbirdp1068.4.2-alt1115.9.0-alt1ALT-PU-2020-1166-1243898Fixed
thunderbirdp968.6.0-alt1102.11.0-alt0.c9.1ALT-PU-2020-1515-1245787Fixed
thunderbirdc10f168.4.2-alt1115.9.0-alt0.c10.1ALT-PU-2020-1166-1243898Fixed
thunderbirdc9f268.6.0-alt1102.11.0-alt0.c9.1ALT-PU-2020-1515-1245787Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      72.0.1

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      End excliding
      68.4.1

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      End excliding
      68.4.1

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*