CVE-2019-11708 log
Source |
|
Severity | High |
Remote | Yes |
Type | Sandbox escape |
Description | An issue has been found in Firefox before 67.0.4, where an insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-997 | firefox | 67.0.3-1 | 67.0.4-1 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
25 Jun 2019 | ASA-201906-20 | AVG-997 | firefox | High | sandbox escape |
References |
---|
https://www.mozilla.org/en-US/security/advisories/mfsa2019-19/#CVE-2019-11708 https://bugzilla.mozilla.org/show_bug.cgi?id=1559858 |