{
  "threat_severity" : "Critical",
  "public_date" : "2019-05-22T00:00:00Z",
  "bugzilla" : {
    "description" : "Mozilla: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7",
    "id" : "1712623",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1712623"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.8",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-120",
  "details" : [ "Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7." ],
  "statement" : "In general, this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail, but it is potentially a risk in browser or browser-like contexts.",
  "acknowledgement" : "Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Bogdan Tara, Gary Kwong, Jan Varga, Jan de Mooij, Jason Kratzer, Olli Pettay, Ronald Crane, Ted Campbell, Tim Guan-tin Chien, and Tyson Smith as the original reporters.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2019-05-23T00:00:00Z",
    "advisory" : "RHSA-2019:1267",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "firefox-0:60.7.0-1.el6_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2019-06-03T00:00:00Z",
    "advisory" : "RHSA-2019:1310",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "thunderbird-0:60.7.0-1.el6_10",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2019-05-23T00:00:00Z",
    "advisory" : "RHSA-2019:1265",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "firefox-0:60.7.0-1.el7_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2019-06-03T00:00:00Z",
    "advisory" : "RHSA-2019:1309",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "thunderbird-0:60.7.0-1.el7_6",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2019-05-23T00:00:00Z",
    "advisory" : "RHSA-2019:1269",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "firefox-0:60.7.0-1.el8_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2019-06-03T00:00:00Z",
    "advisory" : "RHSA-2019:1308",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "thunderbird-0:60.7.0-1.el8_0",
    "impact" : "important"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-9800\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-9800\nhttps://www.mozilla.org/en-US/security/advisories/mfsa2019-14/#CVE-2019-9800" ],
  "name" : "CVE-2019-9800",
  "csaw" : false
}