{"cve": "CVE-2019-17026", "updated": null, "url": null, "affected": [{"ecosystem": "Arch", "package": "thunderbird", "affected": "68.3.1-1", "fixed": "68.4.1-1", "status": "fixed", "ref": "https://security.archlinux.org/AVG-1086"}, {"ecosystem": "Arch", "package": "firefox", "affected": "72.0-1", "fixed": "72.0.1-1", "status": "fixed", "ref": "https://security.archlinux.org/AVG-1085"}, {"ecosystem": "Debian:11", "package": "firefox-esr", "affected": null, "fixed": "68.4.1esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:12", "package": "firefox-esr", "affected": null, "fixed": "68.4.1esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:13", "package": "firefox-esr", "affected": null, "fixed": "68.4.1esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:14", "package": "firefox-esr", "affected": null, "fixed": "68.4.1esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:8", "package": "firefox-esr", "affected": null, "fixed": "68.4.1esr-1~deb8u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DLA-2093-1"}, {"ecosystem": "Debian:9", "package": "firefox-esr", "affected": null, "fixed": "68.4.1esr-1~deb9u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DSA-4600-1"}, {"ecosystem": "Debian:10", "package": "firefox-esr", "affected": null, "fixed": "68.4.1esr-1~deb10u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DSA-4600-1"}, {"ecosystem": "Debian:11", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:12", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:13", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:14", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2019-17026"}, {"ecosystem": "Debian:8", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1-1~deb8u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DLA-2071-1"}, {"ecosystem": "Debian:9", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1-1~deb9u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DSA-4603-1"}, {"ecosystem": "Debian:10", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1-1~deb10u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DSA-4603-1"}, {"ecosystem": "Ubuntu:16.04:LTS", "package": "firefox", "affected": null, "fixed": "72.0.1+build1-0ubuntu0.16.04.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2019-17026"}, {"ecosystem": "Ubuntu:18.04:LTS", "package": "firefox", "affected": null, "fixed": "72.0.1+build1-0ubuntu0.18.04.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2019-17026"}, {"ecosystem": "Ubuntu:20.04:LTS", "package": "firefox", "affected": null, "fixed": "72.0.1+build1-0ubuntu1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2019-17026"}, {"ecosystem": "Ubuntu:16.04:LTS", "package": "thunderbird", "affected": null, "fixed": "1:68.7.0+build1-0ubuntu0.16.04.2", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2019-17026"}, {"ecosystem": "Ubuntu:18.04:LTS", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1+build1-0ubuntu0.18.04.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2019-17026"}, {"ecosystem": "Ubuntu:20.04:LTS", "package": "thunderbird", "affected": null, "fixed": "1:68.4.1+build1-0ubuntu1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2019-17026"}, {"ecosystem": "SUSE:HPE Helion OpenStack 8", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:OpenStack Cloud 7", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:OpenStack Cloud 8", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:OpenStack Cloud Crowbar 8", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Desktop 12 SP4", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 12 SP1", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 12 SP2", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 12 SP3", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Software Development Kit 12 SP4", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Software Development Kit 12 SP5", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP1-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP2-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP2-BCL", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP3-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP3-BCL", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP4", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 12 SP4", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP5", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 12 SP5", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Enterprise Storage 5", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-109.101.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0068-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Desktop Applications 15", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-3.66.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0078-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Desktop Applications 15 SP1", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-3.66.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0078-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 11 SP4-LTSS", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-78.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:14268-1"}, {"ecosystem": "SUSE:Linux Enterprise Workstation Extension 15", "package": "MozillaThunderbird", "affected": null, "fixed": "68.4.1-3.66.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0142-1"}, {"ecosystem": "SUSE:Linux Enterprise Workstation Extension 15 SP1", "package": "MozillaThunderbird", "affected": null, "fixed": "68.4.1-3.66.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2020:0142-1"}, {"ecosystem": "openSUSE:Leap 15.1", "package": "MozillaFirefox", "affected": null, "fixed": "68.4.1-lp151.2.24.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2020:0060-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaFirefox", "affected": null, "fixed": "92.0-1.2", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2024:10600-1"}, {"ecosystem": "openSUSE:Leap 15.1", "package": "MozillaThunderbird", "affected": null, "fixed": "68.4.1-lp151.2.22.2", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2020:0094-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaThunderbird", "affected": null, "fixed": "91.1.1-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2024:10601-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "firefox-esr", "affected": null, "fixed": "128.5.1-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2024:14572-1"}, {"ecosystem": "Red Hat:enterprise_linux:7::client", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el7_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0085"}, {"ecosystem": "Red Hat:enterprise_linux:7::server", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el7_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0085"}, {"ecosystem": "Red Hat:enterprise_linux:7::workstation", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el7_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0085"}, {"ecosystem": "Red Hat:enterprise_linux:6::client", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el6_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0086"}, {"ecosystem": "Red Hat:enterprise_linux:6::computenode", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el6_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0086"}, {"ecosystem": "Red Hat:enterprise_linux:6::server", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el6_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0086"}, {"ecosystem": "Red Hat:enterprise_linux:6::workstation", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el6_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0086"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el8_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0111"}, {"ecosystem": "Red Hat:rhel_e4s:8.0::appstream", "package": "firefox", "affected": null, "fixed": "0:68.4.1-1.el8_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0295"}, {"ecosystem": "Red Hat:enterprise_linux:7::client", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el7_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0120"}, {"ecosystem": "Red Hat:enterprise_linux:7::server", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el7_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0120"}, {"ecosystem": "Red Hat:enterprise_linux:7::workstation", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el7_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0120"}, {"ecosystem": "Red Hat:enterprise_linux:6::client", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el6_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0123"}, {"ecosystem": "Red Hat:enterprise_linux:6::server", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el6_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0123"}, {"ecosystem": "Red Hat:enterprise_linux:6::workstation", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el6_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0123"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el8_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0127"}, {"ecosystem": "Red Hat:rhel_e4s:8.0::appstream", "package": "thunderbird", "affected": null, "fixed": "0:68.4.1-2.el8_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2020:0292"}]}