Rapid7 Vulnerability & Exploit Database

SUSE: CVE-2019-9811: SUSE Linux Security Advisory

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

SUSE: CVE-2019-9811: SUSE Linux Security Advisory

Severity
5
CVSS
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
Published
07/09/2019
Created
07/18/2019
Added
07/18/2019
Modified
10/22/2021

Description

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Solution(s)

  • suse-upgrade-firefox-atk-lang
  • suse-upgrade-firefox-gdk-pixbuf-lang
  • suse-upgrade-firefox-gdk-pixbuf-query-loaders
  • suse-upgrade-firefox-gdk-pixbuf-thumbnailer
  • suse-upgrade-firefox-gio-branding-upstream
  • suse-upgrade-firefox-glib2-lang
  • suse-upgrade-firefox-glib2-tools
  • suse-upgrade-firefox-gtk3-branding-upstream
  • suse-upgrade-firefox-gtk3-data
  • suse-upgrade-firefox-gtk3-immodule-amharic
  • suse-upgrade-firefox-gtk3-immodule-inuktitut
  • suse-upgrade-firefox-gtk3-immodule-multipress
  • suse-upgrade-firefox-gtk3-immodule-thai
  • suse-upgrade-firefox-gtk3-immodule-vietnamese
  • suse-upgrade-firefox-gtk3-immodule-xim
  • suse-upgrade-firefox-gtk3-immodules-tigrigna
  • suse-upgrade-firefox-gtk3-lang
  • suse-upgrade-firefox-gtk3-tools
  • suse-upgrade-firefox-libatk-1_0-0
  • suse-upgrade-firefox-libcairo-gobject2
  • suse-upgrade-firefox-libcairo2
  • suse-upgrade-firefox-libffi4
  • suse-upgrade-firefox-libffi7
  • suse-upgrade-firefox-libgdk_pixbuf-2_0-0
  • suse-upgrade-firefox-libgtk-3-0
  • suse-upgrade-firefox-libharfbuzz0
  • suse-upgrade-firefox-libpango-1_0-0
  • suse-upgrade-libfirefox-gio-2_0-0
  • suse-upgrade-libfirefox-glib-2_0-0
  • suse-upgrade-libfirefox-gmodule-2_0-0
  • suse-upgrade-libfirefox-gobject-2_0-0
  • suse-upgrade-libfirefox-gthread-2_0-0
  • suse-upgrade-libfreebl3
  • suse-upgrade-libfreebl3-32bit
  • suse-upgrade-libfreebl3-hmac
  • suse-upgrade-libfreebl3-hmac-32bit
  • suse-upgrade-libsoftokn3
  • suse-upgrade-libsoftokn3-32bit
  • suse-upgrade-libsoftokn3-hmac
  • suse-upgrade-libsoftokn3-hmac-32bit
  • suse-upgrade-mozilla-nspr
  • suse-upgrade-mozilla-nspr-32bit
  • suse-upgrade-mozilla-nspr-devel
  • suse-upgrade-mozilla-nss
  • suse-upgrade-mozilla-nss-32bit
  • suse-upgrade-mozilla-nss-certs
  • suse-upgrade-mozilla-nss-certs-32bit
  • suse-upgrade-mozilla-nss-devel
  • suse-upgrade-mozilla-nss-sysinit
  • suse-upgrade-mozilla-nss-sysinit-32bit
  • suse-upgrade-mozilla-nss-tools
  • suse-upgrade-mozillafirefox
  • suse-upgrade-mozillafirefox-branding-sle
  • suse-upgrade-mozillafirefox-branding-sled
  • suse-upgrade-mozillafirefox-branding-upstream
  • suse-upgrade-mozillafirefox-buildsymbols
  • suse-upgrade-mozillafirefox-devel
  • suse-upgrade-mozillafirefox-translations-common
  • suse-upgrade-mozillafirefox-translations-other
  • suse-upgrade-mozillathunderbird
  • suse-upgrade-mozillathunderbird-buildsymbols
  • suse-upgrade-mozillathunderbird-translations-common
  • suse-upgrade-mozillathunderbird-translations-other

insightVM

Advanced vulnerability management analytics and reporting.
Key Features
  • Lightweight Endpoint Agent
  • Live Dashboards
  • Real Risk Prioritization
  • IT-Integrated Remediation Projects
  • Cloud, Virtual, and Container Assessment
  • Integrated Threat Feeds
  • Easy-to-Use RESTful API
  • Automation-Assisted Patching
  • Automated Containment
Free InsightVM Trial View All Features

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;