As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9811 Reference (s):
- GENTOO:GLSA-201908-12
- URL: https://security.gentoo.org/glsa/201908-12
- GENTOO:GLSA-201908-20
- URL: https://security.gentoo.org/glsa/201908-20
- https://bugzilla.mozilla.org/show_bug.cgi?id=1538007

