Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

Zoeken in Support

Vermijd ondersteuningsscams. We zullen u nooit vragen een telefoonnummer te bellen, er een sms naar te sturen of persoonlijke gegevens te delen. Meld verdachte activiteit met de optie ‘Misbruik melden’.

Meer info

Deze conversatie is gearchiveerd. Stel een nieuwe vraag als u hulp nodig hebt.

When will CVE-2019-11754 will be patched on ESR 68 ?

  • 3 antwoorden
  • 1 heeft dit probleem
  • 17 weergaven
  • Laatste antwoord van philipp

more options

Dear All From what I see this Vulnerability , is only patched in 69.0.1 https://www.mozilla.org/en-US/security/advisories/mfsa2019-31/ But there have been later ESR 68.2.0 patched released that does not have this mitigated . Will 68 channel ever will get this patched , or will we need to wait for ESR 69 ? When is that supposed to be released ?

Dear All From what I see this Vulnerability , is only patched in 69.0.1 https://www.mozilla.org/en-US/security/advisories/mfsa2019-31/ But there have been later ESR 68.2.0 patched released that does not have this mitigated . Will 68 channel ever will get this patched , or will we need to wait for ESR 69 ? When is that supposed to be released ?

Gekozen oplossing

the bug referenced in https://www.mozilla.org/en-US/security/advisories/mfsa2019-31/ hasn't been made public yet unfortunately, so you won't be able to confirm this by yourself yet :-/

the underlying cause was just introduced in Firefox 69 though, so 69.0 is the only version affected by this vulnerability.

Dit antwoord in context lezen 👍 1

Alle antwoorden (3)

more options

hello, firefox 68esr is not affected by CVE-2019-11754.

more options

Thanks

From this source where many security tools gather their information for baseline scans (e.g. Qualys and such) it says that this is affected FF under 69.0.1 and does not mention ESR the same as CVE-2019-11753 for example: https://www.cvedetails.com/vulnerability-list/vendor_id-452/product_id-3264/Mozilla-Firefox.html

is there any place on line that confirm that this vuln does not affect ESR 68 ?

more options

Gekozen oplossing

the bug referenced in https://www.mozilla.org/en-US/security/advisories/mfsa2019-31/ hasn't been made public yet unfortunately, so you won't be able to confirm this by yourself yet :-/

the underlying cause was just introduced in Firefox 69 though, so 69.0 is the only version affected by this vulnerability.