VDB

GCVE-110-MAGEIA-2020-9

GCVE-110-MAGEIA-2020-9
Advisory Published
Vulnetix · Advisory published January 5, 2020
The updated packages fix security vulnerabilities: A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2. (CVE-2019-11707) Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2. (CVE-2019-11708) The mozjs60 package has been updated to version 60.9.0, fixing these issues and other bugs. The gjs package has been rebuilt against the updated mozjs60.

Affected Products

VendorProductVersionsPlatforms
Mageiamozjs600 (affected), 60.9.0-1.mga7 (unaffected), 0 (affected), 60.9.0-1.mga7 (unaffected)
Mageiagjs0 (affected), 1.56.2-1.1.mga7 (unaffected), 0 (affected), 1.56.2-1.1.mga7 (unaffected)
Mageiarpm4.14.2.1-13.mga7 (unaffected), 0 (affected)

Browse GCVE Records

74,352 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›