Mozilla · Thunderbird · CVE-2024-2616
**Name of the Vulnerable Software and Affected Versions**
Firefox ESR versions prior to 115.9
Thunderbird versions prior to 115.9
**Description**
The issue is related to incorrect clearing or release of resources, potentially allowing a remote attacker to impact the confidentiality, availability, and integrity of protected information. The behavior for out-of-memory conditions was changed to crash instead of attempting to continue, in order to harden against exploitation.
**Recommendations**
For Firefox ESR versions prior to 115.9, update to version 115.9 or later.
For Thunderbird versions prior to 115.9, update to version 115.9 or later.