Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1829029%2C1888538%2C1900394%2C1904059%2C1917742%2C1919809%2C1923706 CVE-2024-10467
CRITICAL
Record summary
CVE-2024-10467 has a selected CVSS score of 9.8 (critical).
Description
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 29, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
FirefoxBrowse Mozilla / FirefoxDefault status: unknown | CVE List | Before 132 | affected |
Firefox ESRBrowse Mozilla / Firefox ESRDefault status: unknown | CVE List | Before 128.4 | affected |
ThunderbirdBrowse Mozilla / ThunderbirdDefault status: unknown | CVE List | Before 128.4 | affected |
| Before 132 | affected | ||
| Before 12.8.4 | affected |
References
8lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/10/msg00034.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/11/msg00001.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-10467 mozilla.org
https://www.mozilla.org/security/advisories/mfsa2024-55 mozilla.org
https://www.mozilla.org/security/advisories/mfsa2024-56 mozilla.org
https://www.mozilla.org/security/advisories/mfsa2024-58 mozilla.org
https://www.mozilla.org/security/advisories/mfsa2024-59