PT-2024-3491 · Mozilla+4 · Firefox+4

Ronald Crane

·

Published

2024-04-16

·

Updated

2025-03-14

·

CVE-2024-3862

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 125
Description The issue is related to the MarkStack assignment operator, part of the JavaScript engine, which could access uninitialized memory if used in a self-assignment. This could allow a remote attacker to cause a denial of service.
Recommendations For versions prior to 125, update to a version that contains a fix for this issue to prevent potential exploitation. As a temporary workaround, consider restricting the use of the MarkStack assignment operator in self-assignments until a patch is available.

Exploit

Fix

Use of Uninitialized Resource

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15839
ALT-PU-2024-6765
BDU:2024-03793
CVE-2024-3862
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13907-1
OPENSUSE-SU-2024:14572-1
USN-6747-1
USN-6747-2

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu