CVE-2024-1557: High severity Mozilla Firefox vulnerability
Last updated 24 July 2024
Other sources
Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.2-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1557?
CVE-2024-1557 has a high severity due to the potential for memory corruption leading to arbitrary code execution.
How do I fix CVE-2024-1557?
To fix CVE-2024-1557, update Firefox to version 123 or later, or to Debian's firefox package version 135.0.1-1 or later.
What versions of Firefox are affected by CVE-2024-1557?
CVE-2024-1557 affects Firefox version 122 and earlier.
Is CVE-2024-1557 exploitable?
While not confirmed, evidence suggests that CVE-2024-1557 could potentially be exploited to execute arbitrary code.
Who is the vendor for CVE-2024-1557?
The vendor for CVE-2024-1557 is Mozilla, the organization behind the Firefox browser.