PT-2024-3485 · Mozilla+10 · Thunderbird+12

Ronald Crane

·

Published

2024-04-15

·

Updated

2025-09-22

·

CVE-2024-3861

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 125 Firefox ESR versions prior to 115.10 Thunderbird versions prior to 115.10
Description The issue is related to the use of memory after it has been freed due to incorrect data movement in the AlignedBuffer structure. This could result in an incorrect reference count and later use-after-free. The vulnerability may allow a remote attacker to cause a denial of service.
Recommendations For Firefox versions prior to 125, update to version 125 or later to resolve the issue. For Firefox ESR versions prior to 115.10, update to version 115.10 or later to resolve the issue. For Thunderbird versions prior to 115.10, update to version 115.10 or later to resolve the issue.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:1908
ALSA-2024:1912
ALSA-2024:1939
ALSA-2024:1940
ALT-PU-2024-13897
ALT-PU-2024-14442
ALT-PU-2024-14892
ALT-PU-2024-15175
ALT-PU-2024-15839
ALT-PU-2024-15841
ALT-PU-2024-6719
ALT-PU-2024-6721
ALT-PU-2024-6765
ALT-PU-2024-7489
ALT-PU-2024-7685
BDU:2024-03786
CESA-2024_1912
CESA-2024_1939
CVE-2024-3861
DLA-3790-1
DLA-3791-1
DSA-5663-1
DSA-5670-1
MGASA-2024-0151
MGASA-2024-0153
OESA-2024-1786
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13884-1
OPENSUSE-SU-2024:13907-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024_1350-1
OPENSUSE-SU-2024_1437-1
OPENSUSE-SU-2024_1770-1
RHSA-2024:1904
RHSA-2024:1905
RHSA-2024:1906
RHSA-2024:1907
RHSA-2024:1908
RHSA-2024:1909
RHSA-2024:1910
RHSA-2024:1911
RHSA-2024:1912
RHSA-2024:1934
RHSA-2024:1935
RHSA-2024:1936
RHSA-2024:1937
RHSA-2024:1938
RHSA-2024:1939
RHSA-2024:1940
RHSA-2024:1941
RHSA-2024:1982
RHSA-2024_1908
RHSA-2024_1910
RHSA-2024_1912
RHSA-2024_1935
RHSA-2024_1939
RHSA-2024_1940
RLSA-2024:1908
RLSA-2024:1912
SUSE-SU-2024:1319-1
SUSE-SU-2024:1350-1
SUSE-SU-2024:1437-1
SUSE-SU-2024:1676-1
SUSE-SU-2024:1770-1
USN-6747-1
USN-6747-2
USN-6750-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu