[3.10] firefox-esr: sandbox escape using Prompt:Open (CVE-2019-11708)
Insufficient vetting of parameters passed with the `Prompt:Open`
IPC message between child and parent processes can result in the non-sandboxed
parent process opening web content chosen by a compromised child process.
When combined with additional vulnerabilities
this could result in executing arbitrary code on the user’s computer.
Fixed In Version:
Firefox ESR 60.7.2
(from redmine: issue id 10602, created on 2019-06-21, closed on 2019-06-28)
community/firefox-esr: security upgrade to 60.7.2 (CVE-2019-11708) fixes #10602