CVE-2024-4775: Medium severity Mozilla Firefox vulnerability
An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. Note: This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.
Other sources
An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. Note: This issue only affects the application when the profiler is running.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 130.0.1-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126 - Upgrade
Upgrade
firefoxto a version that resolves this vulnerability.Fixed in 126
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4775?
CVE-2024-4775 has been classified as a vulnerability that can potentially lead to invalid memory access and undefined behavior.
How do I fix CVE-2024-4775?
To fix CVE-2024-4775, update your Firefox browser to version 126 or later.
Which versions of Firefox are affected by CVE-2024-4775?
CVE-2024-4775 affects all versions of Firefox prior to version 126.
Does CVE-2024-4775 affect Firefox when the profiler is not running?
No, CVE-2024-4775 only affects Firefox when the built-in profiler is active.
What type of impact can result from CVE-2024-4775?
CVE-2024-4775 can result in undefined behavior due to invalid memory access.