PT-2024-1355 · Mozilla+4 · Firefox+4

Yangkang

·

Published

2024-01-23

·

Updated

2024-12-27

·

CVE-2024-0745

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 122
Description The WebAudio OscillatorNode object in Mozilla Firefox was susceptible to a stack buffer overflow, potentially leading to a crash. This issue is related to a buffer overflow in memory, which could allow a remote attacker to cause a denial of service or execute arbitrary code.
Recommendations For versions prior to 122, update to version 122 or later to resolve the issue. As a temporary workaround, consider disabling the WebAudio component until a patch is available. Restrict access to potentially vulnerable web pages to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-1368
ALT-PU-2024-13898
ALT-PU-2024-15839
ALT-PU-2024-15840
BDU:2024-00809
CVE-2024-0745
OESA-2024-2096
OESA-2024-2097
OESA-2024-2098
OESA-2024-2100
OPENSUSE-SU-2024:13626-1
OPENSUSE-SU-2024:14572-1
USN-6610-1
USN-6610-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Firefox
Ubuntu