CVE-2019-17009 log

Source
Severity Medium
Remote No
Type Privilege escalation
Description
A privilege escalation vulnerability has been found in Firefox before 71.0. When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service.
Group Package Affected Fixed Severity Status Ticket
AVG-1071 firefox 70.0.1-3 71.0-1 Critical Fixed
Date Advisory Group Package Severity Type
03 Dec 2019 ASA-201912-1 AVG-1071 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2019-36/#CVE-2019-17009
https://bugzilla.mozilla.org/show_bug.cgi?id=1510494