CVE-2019-11741

Priority
Description
A compromised sandboxed content process can perform a Universal Cross-site
Scripting (UXSS) attack on content from any site it can cause to be loaded
in the same process. Because addons.mozilla.org and accounts.firefox.com
have close ties to the Firefox product, malicious manipulation of these
sites within the browser can potentially be used to modify a user's Firefox
configuration. These two sites will now be isolated into their own process
and not allowed to be loaded in a standard content process. This
vulnerability affects Firefox < 69.
Assigned-to
chrisccoulson
Notes
tyhicksmozjs contains a copy of the SpiderMonkey JavaScript engine
Package
Upstream:released (69.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (69.0+build2-0ubuntu0.16.04.4)
Ubuntu 18.04 LTS (Bionic Beaver):released (69.0+build2-0ubuntu0.18.04.1)
Ubuntu 19.04 (Disco Dingo):released (69.0+build2-0ubuntu0.19.04.1)
Ubuntu 19.10 (Eoan):released (69.0.1+build1-0ubuntu2)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.04 (Disco Dingo):DNE
Ubuntu 19.10 (Eoan):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
Ubuntu 19.10 (Eoan):needs-triage
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 19.04 (Disco Dingo):needs-triage
Ubuntu 19.10 (Eoan):needs-triage
Package
Priority: Low
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
Ubuntu 19.10 (Eoan):needs-triage
More Information

Updated: 2019-10-18 02:43:45 UTC (commit cccfc4426d8c1fbf582a89d981fe7fc812124543)