First published: Tue Jul 09 2024(Updated: )
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 131.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.16.0esr-1~deb11u1 1:115.12.0-1~deb12u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 | |
Thunderbird | <115.13 | 115.13 |
Thunderbird | <128 | 128 |
Firefox | <128 | 128 |
Firefox ESR | <115.13 | 115.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-6600 has been rated as a high-severity vulnerability due to the potential for out-of-bounds memory access.
To fix CVE-2024-6600, update Mozilla Thunderbird to version 128 or later and Mozilla Firefox to version 128 or later.
CVE-2024-6600 affects Mozilla Thunderbird and Mozilla Firefox versions prior to 128, as well as specific Debian packages.
CVE-2024-6600 is an out-of-bounds access vulnerability that can occur during the allocation of private shader memory.
There is no known workaround for CVE-2024-6600, so updating to the latest versions is recommended.