CVE-2024-1552: High severity Mozilla Thunderbird vulnerability
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior. Note: This issue only affects 32-bit ARM devices.
Other sources
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.Note: This issue only affects 32-bit ARM devices.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-06/#CVE-2024-1552
— Red Hat
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.Note: This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
— Launchpad
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.Note: This issue only affects 32-bit ARM devices.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.9.0esr-1~deb12u1Fixed in 128.9.0esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:128.9.0esr-1~deb11u1Fixed in 1:128.8.0esr-1~deb12u1Fixed in 1:128.9.0esr-1~deb12u1Fixed in 1:128.9.0esr-1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 115.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1552?
CVE-2024-1552 is classified as a vulnerability that may lead to unexpected numeric conversions and potential undefined behavior.
How do I fix CVE-2024-1552?
To fix CVE-2024-1552, update affected software to versions 115.8 for Firefox ESR, 123 for Firefox, or 115.8 for Thunderbird.
Which software is affected by CVE-2024-1552?
CVE-2024-1552 affects Mozilla Firefox (up to version 123), Firefox ESR (up to version 115.8), and Thunderbird (up to version 115.8).
Does CVE-2024-1552 affect 64-bit systems?
CVE-2024-1552 only affects 32-bit ARM devices, thus 64-bit systems are not impacted.
What behavior is impacted by CVE-2024-1552?
CVE-2024-1552 can lead to incorrect code generation, resulting in unexpected numeric conversions or undefined behavior.