PT-2024-4247 · Mozilla+11 · Firefox+14
Thomas Rinsma
·
Published
2023-10-30
·
Updated
2026-02-02
·
CVE-2024-4367
CVSS v3.1
8.8
High
| AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Alma Linux (affected versions not specified)
Debian firefox-esr versions 115.11.0esr-1~deb10u1
Mozilla Firefox (affected versions not specified)
Mozilla Thunderbird (affected versions not specified)
Network Security Services (NSS) (affected versions not specified)
openSUSE (affected versions not specified)
Rocky Linux (affected versions not specified)
SUSE (affected versions not specified)
Description:
Multiple security issues have been identified and addressed in recent updates for various software packages, including Mozilla Firefox, Mozilla Thunderbird, and Network Security Services (NSS). These vulnerabilities could potentially lead to arbitrary code execution, denial of service, or other security compromises. The updates include fixes for use-after-free vulnerabilities, denial-of-service issues, and other security flaws. The specific details of these vulnerabilities are extensive and encompass a range of components within the affected software. The updates address issues such as HTTP/2 frame handling, animation timeline vulnerabilities, and potential memory safety concerns.
Recommendations:
- Upgrade Mozilla Firefox to the latest available version.
- Upgrade Mozilla Thunderbird to the latest available version.
- Upgrade Network Security Services (NSS) to the latest available version.
- Update Alma Linux packages to the latest versions.
- Update Debian firefox-esr packages to version 115.11.0esr-1~deb10u1.
- Update openSUSE packages to the latest versions.
- Update Rocky Linux packages to the latest versions.
- Update SUSE packages to the latest versions.
Exploit
Fix
Improper Check for Exceptional Conditions
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Confluence
Firefox
Firefox Esr
Linuxmint
Pdf.Js
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu