CVE-2024-4772: Weak RNG
An HTTP digest authentication nonce value was generated using rand() which could lead to predictable values. This vulnerability affects Firefox < 126.
Other sources
An HTTP digest authentication nonce value was generated using rand() which could lead to predictable values.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 130.0.1-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4772?
CVE-2024-4772 has a moderate severity level due to the potential for predictable nonce values in HTTP digest authentication.
How do I fix CVE-2024-4772?
To resolve CVE-2024-4772, upgrade to Mozilla Firefox version 126 or later.
Which versions of Firefox are affected by CVE-2024-4772?
CVE-2024-4772 affects all versions of Firefox prior to 126.
What does CVE-2024-4772 affect?
CVE-2024-4772 affects the HTTP digest authentication mechanism in Mozilla Firefox by using a weak nonce value.
Is there a specific version of Firefox recommended to mitigate CVE-2024-4772?
Yes, upgrading to Mozilla Firefox version 126 or later is recommended to mitigate CVE-2024-4772.