CVE-2024-6614: Incorrect listing of stack frames
Last updated 24 July 2024
Other sources
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 128
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6614?
CVE-2024-6614 is considered a medium severity vulnerability affecting Mozilla Firefox and Thunderbird.
How do I fix CVE-2024-6614?
To fix CVE-2024-6614, update your Mozilla Firefox or Thunderbird to version 128 or later.
What are the impacted versions for CVE-2024-6614?
CVE-2024-6614 affects Mozilla Firefox and Thunderbird versions earlier than 128.
What is the nature of CVE-2024-6614?
CVE-2024-6614 involves a loop in the frame iterator when processing specific WebAssembly frames, potentially causing incorrect stack traces.
Is there a workaround for CVE-2024-6614 before updating?
There is no known workaround for CVE-2024-6614, so it is recommended to update to the latest version as soon as possible.