PT-2024-32767 · Mozilla+4 · Firefox+4

Hanno Böck

·

Published

2024-05-14

·

Updated

2025-03-14

·

CVE-2024-4772

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 126
Description A predictable HTTP digest authentication nonce value was generated using the rand() function.
Recommendations For Firefox versions prior to 126, update to version 126 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10126
ALT-PU-2024-10593
ALT-PU-2024-15839
ALT-PU-2024-7772
CVE-2024-4772
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13980-1
OPENSUSE-SU-2024:14572-1
USN-6779-1
USN-6779-2

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu