← Search the atlas
SUSE-SU-2019:1684-1
Not scored
Security update for MozillaFirefox
This update for MozillaFirefox fixes the following issues:
- Mozilla Firefox Firefox 60.7.2
MFSA 2019-19 (bsc#1138872)
- CVE-2019-11708: Fix sandbox escape using Prompt:Open.
* Insufficient vetting of parameters passed with the Prompt:Open IPC
message between child and parent processes could result in the non-sandboxed
parent process opening web content chosen by a compromised child process.
When combined with additional vulnerabilities this could result in executing
arbitrary code on the user's computer.
Exploit probability
Not scored
Published
June 22, 2019
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Enterprise Storage 4
MozillaFirefox
SUSE:Enterprise Storage 5
MozillaFirefox
SUSE:Linux Enterprise Desktop 12 SP3
MozillaFirefox
SUSE:Linux Enterprise Desktop 12 SP4
MozillaFirefox
SUSE:Linux Enterprise Server 12 SP1-LTSS
MozillaFirefox
SUSE:Linux Enterprise Server 12 SP2-BCL
MozillaFirefox
SUSE:Linux Enterprise Server 12 SP2-LTSS
MozillaFirefox
SUSE:Linux Enterprise Server 12 SP3
MozillaFirefox
SUSE:Linux Enterprise Server 12 SP3-LTSS
MozillaFirefox
SUSE:Linux Enterprise Server 12 SP4
MozillaFirefox
SUSE:Linux Enterprise Server 12-LTSS
MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP1
MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP4
MozillaFirefox
SUSE:Linux Enterprise Software Development Kit 12 SP3
MozillaFirefox
SUSE:Linux Enterprise Software Development Kit 12 SP4
MozillaFirefox
SUSE:OpenStack Cloud 7
MozillaFirefox
SUSE:OpenStack Cloud 8
MozillaFirefox
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2019:1684-1
This update for MozillaFirefox fixes the following issues:
- Mozilla Firefox Firefox 60.7.2
MFSA 2019-19 (bsc#1138872)
- CVE-2019-11708: Fix sandbox escape using Prompt:Open.
* Insufficient vetting of parameters passed with the Prompt:Open IPC
message between child and parent processes could result in the non-sandboxed
parent process opening web content chosen by a compromised child process.
When combined with additional vulnerabilities this could result in executing
arbitrary code on the user's computer.
View original source ↗
05 / REFERENCES
Further evidence