CVE-2024-6606: Out-of-bounds read in clipboard component
Clipboard code failed to check the index on an array access. This could have lead to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Other sources
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 128
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6606?
CVE-2024-6606 is categorized as a moderate severity vulnerability due to its potential for out-of-bounds read access affecting Firefox and Thunderbird.
How do I fix CVE-2024-6606?
To mitigate CVE-2024-6606, users should update Firefox and Thunderbird to versions 128 or higher.
Which software is affected by CVE-2024-6606?
CVE-2024-6606 affects Mozilla Firefox versions prior to 128 and Mozilla Thunderbird versions prior to 128.
What vulnerabilities are similar to CVE-2024-6606?
Similar vulnerabilities to CVE-2024-6606 may involve out-of-bounds access issues in software applications.
When was CVE-2024-6606 disclosed?
CVE-2024-6606 was disclosed in 2024 and affects previous versions of popular Mozilla software.