PT-2024-6065 · Mozilla+10 · Thunderbird+12

Kim Do Hun

·

Published

2024-05-14

·

Updated

2025-03-14

·

CVE-2024-4767

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 126 Firefox ESR versions prior to 115.11 Thunderbird versions prior to 115.11
Description The issue is related to the improper deletion of IndexedDB files when the browser.privatebrowsing.autostart preference is enabled and the window is closed. This preference is disabled by default in Firefox. The vulnerability can be exploited by a remote attacker to gain access to confidential data due to errors in data type conversion when the private browsing mode autostart is enabled.
Recommendations For Firefox versions prior to 126, update to version 126 or later to resolve the issue. For Firefox ESR versions prior to 115.11, update to version 115.11 or later to resolve the issue. For Thunderbird versions prior to 115.11, update to version 115.11 or later to resolve the issue.

Exploit

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2883
ALSA-2024:2888
ALSA-2024:3783
ALSA-2024:3784
ALT-PU-2024-13897
ALT-PU-2024-14442
ALT-PU-2024-14892
ALT-PU-2024-15175
ALT-PU-2024-15839
ALT-PU-2024-15841
ALT-PU-2024-7772
ALT-PU-2024-7980
ALT-PU-2024-7982
BDU:2024-06889
CESA-2024_3783
CESA-2024_3784
CVE-2024-4767
DLA-3815-1
DLA-3817-1
DSA-5691-1
DSA-5693-1
INFSA-2024_2883
INFSA-2024_2888
INFSA-2024_3783
INFSA-2024_3784
MGASA-2024-0189
MGASA-2024-0191
OESA-2024-1786
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13980-1
OPENSUSE-SU-2024:13981-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024_1770-1
OPENSUSE-SU-2024_1858-1
RHSA-2024:2881
RHSA-2024:2882
RHSA-2024:2883
RHSA-2024:2884
RHSA-2024:2885
RHSA-2024:2886
RHSA-2024:2887
RHSA-2024:2888
RHSA-2024:2903
RHSA-2024:2904
RHSA-2024:2905
RHSA-2024:2906
RHSA-2024:2911
RHSA-2024:2912
RHSA-2024:2913
RHSA-2024:3338
RHSA-2024:3783
RHSA-2024:3784
RHSA-2024_2881
RHSA-2024_2883
RHSA-2024_2888
RHSA-2024_2913
RHSA-2024_3783
RHSA-2024_3784
RLSA-2024:2888
RLSA-2024:3783
RLSA-2024:3784
SUSE-SU-2024:1676-1
SUSE-SU-2024:1770-1
SUSE-SU-2024:1858-1
USN-6779-1
USN-6779-2
USN-6782-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu