Bugzilla – Bug 1149321
VUL-0: CVE-2019-5849: MozillaFirefox: Out-of-bounds read in Skia
Last modified: 2019-11-20 16:09:19 UTC
CVE-2019-5849: Out-of-bounds read in Skia Reporter Zhen Zhou of NSFOCUS Security Team Impact moderate Description An out-of-bounds read vulnerability exists in the Skia graphics library, allowing for the possible leaking of data from memory. References: https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/#CVE-2019-5849 https://bugzilla.mozilla.org/show_bug.cgi?id=1555838 https://bugzilla.redhat.com/show_bug.cgi?id=1748674 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-5849 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-5849.html
This issue is fixed in Firefox 69. openSUSE uses different versions: openSUSE:Leap:15.0 60.0esr openSUSE:Leap:15.1 60.6.2esr openSUSE:Leap:15.2 68.2.0esr openSUSE:Factory 70.0.1 SLE is also using only ESR versions and not Firefox 69. Closing bug as invalid.