CVE-2024-4767: Medium severity Mozilla Thunderbird vulnerability
If the browser.privatebrowsing.autostart preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/#CVE-2024-4767
Other sources
If the browser.privatebrowsing.autostart preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
— Launchpad
If the browser.privatebrowsing.autostart preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox.
— Mozilla
If the browser.privatebrowsing.autostart preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Thunderbird.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 130.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 115.15.0esr-1~deb11u1Fixed in 115.14.0esr-1~deb12u1Fixed in 115.15.0esr-1~deb12u1Fixed in 115.15.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.15.0-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.15.0-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.2.1esr-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 126 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 115.11 - Configuration
Ensure the preference browser.privatebrowsing.autostart is disabled so IndexedDB files are properly deleted on window close.
Firefox/Thunderbird browser.privatebrowsing.autostart = false
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4767?
CVE-2024-4767 has a moderate severity rating due to the potential risk of unauthorized access to IndexedDB files.
How do I fix CVE-2024-4767?
To mitigate CVE-2024-4767, update your Firefox or Thunderbird to versions 115.11 or above.
Which software is affected by CVE-2024-4767?
CVE-2024-4767 affects Mozilla Firefox ESR prior to 115.11, Mozilla Thunderbird prior to 115.11, and regular Firefox prior to version 126.
Does enabling private browsing in Firefox trigger CVE-2024-4767?
Yes, if 'browser.privatebrowsing.autostart' is enabled, CVE-2024-4767 can lead to IndexedDB files not being deleted properly.
Is CVE-2024-4767 a critical vulnerability?
CVE-2024-4767 is not considered critical, but it poses a security risk if sensitive data remains accessible after a private browsing session.