USN-6710-1: Firefox vulnerabilities
Manfred Paul discovered that Firefox did not properly perform bounds checking during range analysis, leading to an out-of-bounds write vulnerability. A attacker could use this to cause a denial of service, or execute arbitrary code. (CVE-2024-29943) Manfred Paul discovered that Firefox incorrectly handled MessageManager listeners under certain circumstances. An attacker who was able to inject an event handler into a privileged object may have been able to execute arbitrary code. (CVE-2024-29944)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6710-1?
The severity of USN-6710-1 is critical due to the out-of-bounds write vulnerability that can lead to arbitrary code execution.
How do I fix USN-6710-1?
To fix USN-6710-1, you should update Firefox to version 124.0.1+build1-0ubuntu0.20.04.1 or later.
What vulnerabilities are addressed in USN-6710-1?
USN-6710-1 addresses a critical out-of-bounds write vulnerability identified as CVE-2024-29943.
Can USN-6710-1 cause a denial of service?
Yes, USN-6710-1 can lead to a denial of service if exploited through the out-of-bounds write vulnerability.
Who discovered the vulnerability in USN-6710-1?
The vulnerability in USN-6710-1 was discovered by Manfred Paul.