First published: Tue Jul 09 2024(Updated: )
A mismatch between allocator and deallocator could have lead to memory corruption. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <115.13 | 115.13 |
redhat/thunderbird | <115.13 | 115.13 |
Mozilla Thunderbird | <128 | 128 |
Mozilla Thunderbird | <115.13 | 115.13 |
Mozilla Firefox | <128 | 128 |
Mozilla Firefox ESR | <115.13 | 115.13 |
debian/firefox | 131.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/nss | <=2:3.61-1+deb11u3<=2:3.87.1-1 | 2:3.105-2 |
debian/thunderbird | <=1:115.12.0-1~deb11u1<=1:115.12.0-1~deb12u1 | 1:115.16.0esr-1~deb11u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-6602 is classified as a high severity vulnerability due to the potential for memory corruption.
To fix CVE-2024-6602, update Firefox to version 128 or Thunderbird and Firefox ESR to version 115.13 or above.
CVE-2024-6602 affects Firefox versions less than 128 and Firefox ESR versions less than 115.13.
Exploitation of CVE-2024-6602 may lead to memory corruption, which can potentially allow an attacker to execute arbitrary code.
Users of Firefox, Firefox ESR, and Thunderbird versions below the specified thresholds are vulnerable to CVE-2024-6602.