First published: Tue Aug 06 2024(Updated: )
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 131.0.2-2 | |
Thunderbird | <128.1 | 128.1 |
Firefox | <129.0 | |
Firefox ESR | <128.1.0 | |
Thunderbird | <128.1.0 | |
Firefox | <129 | 129 |
Firefox ESR | <128.1 | 128.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-7528 is classified as a use-after-free vulnerability, which can potentially lead to arbitrary code execution.
To fix CVE-2024-7528, update Firefox to version 129 or newer, or Firefox ESR and Thunderbird to version 128.1 or newer.
Firefox versions prior to 129, Firefox ESR versions prior to 128.1, and Thunderbird versions prior to 128.1 are affected by CVE-2024-7528.
CVE-2024-7528 affects Mozilla Firefox on all platforms where the affected versions are installed.
Yes, patches for CVE-2024-7528 have been released in the latest versions of Firefox, Firefox ESR, and Thunderbird.