PT-2024-7775 · Mozilla+10 · Thunderbird+12

Masato Kinugawa

·

Published

2024-10-01

·

Updated

2025-07-18

·

CVE-2024-9393

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 131 Firefox ESR versions prior to 128.3 Firefox ESR versions prior to 115.16 Thunderbird versions prior to 128.3 Thunderbird versions prior to 131
Description The issue is related to a CORS mechanism error in Mozilla Firefox, Firefox ESR, and the Thunderbird email client, specifically with the resource://pdf.js path. An attacker could exploit this by sending a specially crafted multipart response, allowing them to execute arbitrary JavaScript under the resource://pdf.js origin. This could enable access to cross-origin PDF content, with the level of access varying between desktop and Android versions due to the Site Isolation feature.
Recommendations For Firefox versions prior to 131, update to version 131 or later. For Firefox ESR versions prior to 128.3, update to version 128.3 or later. For Firefox ESR versions prior to 115.16, update to version 115.16 or later. For Thunderbird versions prior to 128.3, update to version 128.3 or later. For Thunderbird versions prior to 131, update to version 131 or later. As a temporary workaround, consider restricting access to the resource://pdf.js path until a patch is available.

Fix

Origin Validation Error

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:7505
ALSA-2024:7552
ALSA-2024:7699
ALSA-2024:7700
ALT-PU-2024-13895
ALT-PU-2024-13897
ALT-PU-2024-13898
ALT-PU-2024-14780
ALT-PU-2024-15087
ALT-PU-2024-15839
ALT-PU-2024-15840
ALT-PU-2024-15841
BDU:2024-09268
CESA-2024_7699
CESA-2024_7700
CVE-2024-9393
DLA-3913-1
DLA-3916-1
DSA-5783-1
DSA-5789-1
INFSA-2024_7505
INFSA-2024_7552
INFSA-2024_7699
INFSA-2024_7700
MGASA-2024-0334
OESA-2024-2275
OESA-2025-1265
OESA-2025-1268
OESA-2025-1835
OPENSUSE-SU-2024:14385-1
OPENSUSE-SU-2024:14394-1
OPENSUSE-SU-2024:14397-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024_3614-1
OPENSUSE-SU-2024_3629-1
RHSA-2024:7505
RHSA-2024:7552
RHSA-2024:7621
RHSA-2024:7622
RHSA-2024:7646
RHSA-2024:7699
RHSA-2024:7700
RHSA-2024:7702
RHSA-2024:7703
RHSA-2024:7704
RHSA-2024:7842
RHSA-2024:7853
RHSA-2024:7854
RHSA-2024:7855
RHSA-2024:7856
RHSA-2024:8166
RHSA-2024:8169
RHSA-2024_7505
RHSA-2024_7552
RHSA-2024_7699
RHSA-2024_7700
RLSA-2024:7699
RLSA-2024:7700
SUSE-SU-2024:3518-1
SUSE-SU-2024:3519-1
SUSE-SU-2024:3603-1
SUSE-SU-2024:3614-1
SUSE-SU-2024:3629-1
USN-7056-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu