Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
https://www.mozilla.org/security/advisories/mfsa2019-23/
https://www.mozilla.org/security/advisories/mfsa2019-22/
https://www.mozilla.org/security/advisories/mfsa2019-21/
https://security.gentoo.org/glsa/201908-20
https://security.gentoo.org/glsa/201908-12
https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1555523
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html