UBUNTU-CVE-2019-9801
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9801
Summary:
Details: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
References: https://ubuntu.com/security/CVE-2019-9801, https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9801, https://www.mozilla.org/en-US/security/advisories/mfsa2019-07/#CVE-2019-9801, https://www.mozilla.org/en-US/security/advisories/mfsa2019-11/#CVE-2019-9801, https://www.cve.org/CVERecord?id=CVE-2019-9801
Affected packages
Package
Name: mozjs52
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
