First published: Tue Apr 16 2024(Updated: )
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 135.0.1-1 | |
Firefox | <125 | 125 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-3855 is classified as a significant vulnerability due to its potential for causing out-of-bounds reads.
To fix CVE-2024-3855, update to Mozilla Firefox version 125 or later.
CVE-2024-3855 affects all versions of Firefox prior to version 125.
CVE-2024-3855 is a JIT optimization vulnerability that can lead to out-of-bounds memory access.
Yes, Debian systems can resolve CVE-2024-3855 by upgrading to the Firefox package version 134.0.2-3 or later.