ArchLinux: 201906-19: firefox-developer-edition: arbitrary code execution
Summary
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop, in Firefox before 67.0.3. This can allow for an exploitable crash. Mozilla has been made aware of targeted attacks in the wild abusing this flaw.
Resolution
Upgrade to 68.0b11-1.
# pacman -Syu "firefox-developer-edition>=68.0b11-1"
The problem has been fixed upstream in version 68.0b11.
References
https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/ https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/ https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 https://security.archlinux.org/CVE-2019-11707
Workaround
None.