---
title: "CVE-2019-11733\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-11733?format=md
keywords: index, follow
---

# CVE-2019-11733

Publication date 16 August 2019

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.8 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2019-11733?format=md#impact-score)

Toggle side navigation

## Description

When a master password is set, it is required to be entered again before
stored passwords can be accessed in the 'Saved Logins' dialog. It was found
that locally stored passwords can be copied to the clipboard thorough the
'copy password' context menu item without re-entering the master password
if the master password had been previously entered in the same session,
allowing for potential theft of stored passwords. This vulnerability
affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 19.04 disco | Fixed 68.0.2+build1-0ubuntu0.19.04.1 |
| 18.04 LTS bionic | Fixed 68.0.2+build1-0ubuntu0.18.04.1 |
| 16.04 LTS xenial | Fixed 68.0.2+build1-0ubuntu0.16.04.1 |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

9.8 · Critical

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 9.8 · Critical |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11733)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-11733)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-11733)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-11733)

### Related Ubuntu Security Notices (USN)

+ [USN-4101-1](https://usn.ubuntu.com/USN-4101-1)
+ Firefox vulnerability
+ 16 August 2019

### Other references

* <https://www.mozilla.org/en-US/security/advisories/mfsa2019-24/#CVE-2019-11733>
* <https://www.cve.org/CVERecord?id=CVE-2019-11733>
