CVE-2024-7522: Critical severity thunderbird vulnerability
Published Aug 6, 2024
·Updated
Editor code failed to check an attribute value. This could have led to an out-of-bounds read.
Affected Software
13 affected componentsFixes available
debian/firefox
131.0.3-1
debian/firefox-esr
115.14.0esr-1~deb11u1128.3.1esr-1~deb11u1115.14.0esr-1~deb12u1128.3.1esr-1~deb12u1128.3.1esr-2
debian/thunderbird<=1:115.12.0-1~deb11u1, <=1:115.12.0-1~deb12u1
1:115.16.0esr-1~deb11u11:115.16.0esr-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<128.1
128.1
Mozilla Thunderbird<115.14
115.14
Mozilla Firefox<129.0
Mozilla Firefox ESR<115.14.0
Mozilla Firefox ESR=128.0
Mozilla Thunderbird<115.14.0
Mozilla Thunderbird=128.0.1
Mozilla Firefox<129
129
Mozilla Firefox ESR<128.1
128.1
Mozilla Firefox ESR<115.14
115.14
Event History
Aug 6, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionWeakness
Sep 16, 2024
Data Sourced
via Ubuntu·08:17 AM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-7522?
CVE-2024-7522 is classified as a high severity vulnerability due to its potential for an out-of-bounds read.
2
How do I fix CVE-2024-7522?
To fix CVE-2024-7522, update to Firefox version 129 or Firefox ESR version 115.14 or higher.
3
Which versions of browsers are affected by CVE-2024-7522?
CVE-2024-7522 affects Firefox versions earlier than 129, Firefox ESR versions earlier than 115.14, and Thunderbird versions earlier than 128.1.
4
What type of vulnerability is CVE-2024-7522?
CVE-2024-7522 is an out-of-bounds read vulnerability stemming from inadequate checks on attribute values.
5
Who is the vendor for CVE-2024-7522?
The vendor for CVE-2024-7522 is Mozilla, which develops both Firefox and Thunderbird.