CVE-2024-4774: Medium severity Mozilla Firefox vulnerability
Last updated 24 July 2024
Other sources
The ShmemCharMapHashEntry() code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.
— NVD
The ShmemCharMapHashEntry() code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 130.0.1-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4774?
The CVE-2024-4774 vulnerability has been classified with a high severity level due to potential undefined behavior affecting the Firefox browser.
How do I fix CVE-2024-4774?
To fix CVE-2024-4774, users should update to Firefox version 130.0.1-1 or higher.
Which versions of Firefox are affected by CVE-2024-4774?
CVE-2024-4774 affects all versions of Firefox prior to 126.
Can CVE-2024-4774 be exploited remotely?
Yes, CVE-2024-4774 may be exploited remotely, making it critical for users to update their browsers.
What functionality is impacted by CVE-2024-4774?
CVE-2024-4774 impacts the ShmemCharMapHashEntry() function in Firefox, leading to potentially undefined behavior.