First published: Tue Jul 09 2024(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <115.13 | 115.13 |
redhat/thunderbird | <115.13 | 115.13 |
Mozilla Thunderbird | <128 | 128 |
Mozilla Thunderbird | <115.13 | 115.13 |
Mozilla Firefox | <128 | 128 |
Mozilla Firefox ESR | <115.13 | 115.13 |
debian/firefox | 131.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/thunderbird | <=1:115.12.0-1~deb11u1<=1:115.12.0-1~deb12u1 | 1:115.16.0esr-1~deb11u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-6604 is classified as a memory safety bug that may allow for memory corruption and potential arbitrary code execution.
To fix CVE-2024-6604, update Firefox and Thunderbird to version 115.13 or later.
CVE-2024-6604 affects Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12.
While CVE-2024-6604 shows evidence of memory corruption, it is presumed that it could potentially be exploited with sufficient effort.
Versions 115.13 and above for Firefox and Thunderbird, and 115.14.0esr for Firefox ESR are safe from CVE-2024-6604.