CVE-2019-11747

Priority
Description
The "Forget about this site" feature in the History pane is intended to
remove all saved user data that indicates a user has visited a site. This
includes removing any HTTP Strict Transport Security (HSTS) settings
received from sites that use it. Due to a bug, sites on the pre-load list
also have their HSTS setting removed. On the next visit to that site if the
user specifies an http: URL rather than secure https: they will not be
protected by the pre-loaded HSTS setting. After that visit the site's HSTS
setting will be restored. This vulnerability affects Firefox < 69 and
Firefox ESR < 68.1.
Assigned-to
chrisccoulson
Notes
tyhicksmozjs contains a copy of the SpiderMonkey JavaScript engine
Package
Upstream:released (69.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (69.0+build2-0ubuntu0.16.04.4)
Ubuntu 18.04 LTS (Bionic Beaver):released (69.0+build2-0ubuntu0.18.04.1)
Ubuntu 20.04 LTS (Focal Fossa):released (69.0.1+build1-0ubuntu2)
Ubuntu 20.10 (Groovy Gorilla):released (69.0.1+build1-0ubuntu2)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 20.04 LTS (Focal Fossa):DNE
Ubuntu 20.10 (Groovy Gorilla):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 20.04 LTS (Focal Fossa):needs-triage
Ubuntu 20.10 (Groovy Gorilla):needs-triage
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 20.04 LTS (Focal Fossa):DNE
Ubuntu 20.10 (Groovy Gorilla):DNE
More Information

Updated: 2020-07-28 18:54:08 UTC (commit 7b6828437fde0509248708fcdb5b0f7587b85bd1)