PT-2024-6042 · Mozilla+7 · Thunderbird+9
Nbars
+1
·
Published
2024-07-10
·
Updated
2025-03-14
·
CVE-2024-7652
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 128
Mozilla Firefox ESR versions prior to 115.13
Mozilla Thunderbird versions prior to 115.13
Mozilla Thunderbird versions prior to 128
Description
The issue is related to a type confusion in Async Generators, potentially leading to memory corruption and an exploitable crash. This could allow a remote attacker to cause a denial of service. The problem is associated with an error in the ECMA-262 specification.
Recommendations
For Mozilla Firefox versions prior to 128, upgrade to version 128 or later.
For Mozilla Firefox ESR versions prior to 115.13, upgrade to version 115.13 or later.
For Mozilla Thunderbird versions prior to 115.13, upgrade to version 115.13 or later.
For Mozilla Thunderbird versions prior to 128, upgrade to version 128 or later.
As a temporary workaround, consider using
std::panic::catch unwind to ensure any exceptions caused by the engine do not impact the availability of the main application.Fix
DoS
Type Confusion
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Thunderbird
Red Hat
Red Os
Rocky Linux