Severity
High
Analysis Summary
CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with
additional vulnerabilities this could result in executing arbitrary code on the user’s computer.
CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for
an exploitable crash.
Impact
Affected Vendors
RedHat
Affected Products
Remediation
CVE-2019-11707 Mozilla: BZ – 1721789
CVE-2019-11708 Mozilla: BZ – 1722673