| Revision Date: | 2019-04-26 | Version: | 1 | | Title: | CVE-2019-9794 on Ubuntu 16.04 LTS (xenial) - negligible. | | Description: | A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
| | Family: | unix | Class: | vulnerability | | Status: | | Reference(s): | CVE-2019-9794
| | Platform(s): | Ubuntu 16.04 LTS
| Product(s): | | | Definition Synopsis | | Ubuntu 16.04 LTS (xenial) is installed. AND Package Information
NOT firefox package in xenial, while related to the CVE in some way, is not affected.
OR NOT firefox-globalmenu package in xenial, while related to the CVE in some way, is not affected.
OR NOT firefox-mozsymbols package in xenial, while related to the CVE in some way, is not affected.
OR NOT firefox-testsuite package in xenial, while related to the CVE in some way, is not affected.
OR NOT thunderbird package in xenial, while related to the CVE in some way, is not affected.
OR NOT thunderbird-globalmenu package in xenial, while related to the CVE in some way, is not affected.
OR NOT thunderbird-gnome-support package in xenial, while related to the CVE in some way, is not affected.
OR NOT thunderbird-mozsymbols package in xenial, while related to the CVE in some way, is not affected.
OR NOT xul-ext-calendar-timezones package in xenial, while related to the CVE in some way, is not affected.
OR NOT xul-ext-gdata-provider package in xenial, while related to the CVE in some way, is not affected.
OR NOT xul-ext-lightning package in xenial, while related to the CVE in some way, is not affected.
|
|