PT-2024-6042 · Mozilla+7 · Thunderbird+9

Nbars

+1

·

Published

2024-07-10

·

Updated

2025-03-14

·

CVE-2024-7652

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 128 Mozilla Firefox ESR versions prior to 115.13 Mozilla Thunderbird versions prior to 115.13 Mozilla Thunderbird versions prior to 128
Description The issue is related to a type confusion in Async Generators, potentially leading to memory corruption and an exploitable crash. This could allow a remote attacker to cause a denial of service. The problem is associated with an error in the ECMA-262 specification.
Recommendations For Mozilla Firefox versions prior to 128, upgrade to version 128 or later. For Mozilla Firefox ESR versions prior to 115.13, upgrade to version 115.13 or later. For Mozilla Thunderbird versions prior to 115.13, upgrade to version 115.13 or later. For Mozilla Thunderbird versions prior to 128, upgrade to version 128 or later. As a temporary workaround, consider using std::panic::catch unwind to ensure any exceptions caused by the engine do not impact the availability of the main application.

Fix

DoS

Type Confusion

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2024:6681
ALSA-2024:6682
ALSA-2024:6683
ALSA-2024:6684
ALT-PU-2024-14780
ALT-PU-2024-14892
ALT-PU-2024-15087
ALT-PU-2024-15175
BDU:2024-06862
CESA-2024_6682
CESA-2024_6684
CVE-2024-7652
DSA-5727-1
DSA-5733-1
GHSA-F67Q-WR6W-23JQ
GHSA-G38C-WH3C-5H9R
INFSA-2024_6681
INFSA-2024_6682
INFSA-2024_6683
INFSA-2024_6684
OESA-2025-1265
OESA-2025-1268
RHSA-2024:6681
RHSA-2024:6682
RHSA-2024:6683
RHSA-2024:6684
RHSA-2024:6719
RHSA-2024:6720
RHSA-2024:6721
RHSA-2024:6722
RHSA-2024:6723
RHSA-2024:6816
RHSA-2024:6838
RHSA-2024:6891
RHSA-2024:6892
RHSA-2024_6681
RHSA-2024_6682
RHSA-2024_6683
RHSA-2024_6684
RLSA-2024:6681
RLSA-2024:6682
RLSA-2024:6683
RLSA-2024:6684

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Thunderbird
Red Hat
Red Os
Rocky Linux