Oval Definition:oval:com.ubuntu.disco:def:2019117080000000
Revision Date:2019-07-23Version:1
Title:CVE-2019-11708 on Ubuntu 19.04 (disco) - high.
Description:Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-11708
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND Package Information
  • firefox package in disco was vulnerable but has been fixed (note: '67.0.4+build1-0ubuntu0.19.04.1').
  • OR thunderbird package in disco was vulnerable but has been fixed (note: '1:60.7.2+build2-0ubuntu0.19.04.1').
  • BACK