CVE-2024-1556: Medium severity Mozilla Firefox vulnerability
Last updated 24 July 2024
Other sources
The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. Note: This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.
— NVD
The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. Note: This issue only affects the application when the profiler is running.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.1-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1556?
CVE-2024-1556 is classified as a medium severity vulnerability due to the potential for invalid memory access and undefined behavior.
How do I fix CVE-2024-1556?
To fix CVE-2024-1556, update Firefox to version 123 or later, or to version 134.0.2-2 if using the Debian package.
Which versions of Firefox are affected by CVE-2024-1556?
CVE-2024-1556 affects all versions of Firefox prior to version 123.
Does CVE-2024-1556 only affect certain environments?
Yes, CVE-2024-1556 only affects the application when the built-in profiler is running.
What type of behavior does CVE-2024-1556 lead to?
CVE-2024-1556 can lead to invalid memory access and undefined behavior within the application.