First published: Mon Mar 25 2024(Updated: )
Manfred Paul discovered that Firefox did not properly perform bounds checking during range analysis, leading to an out-of-bounds write vulnerability. A attacker could use this to cause a denial of service, or execute arbitrary code. (CVE-2024-29943) Manfred Paul discovered that Firefox incorrectly handled MessageManager listeners under certain circumstances. An attacker who was able to inject an event handler into a privileged object may have been able to execute arbitrary code. (CVE-2024-29944)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/firefox | <124.0.1+build1-0ubuntu0.20.04.1 | 124.0.1+build1-0ubuntu0.20.04.1 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.