USN-6747-1

Source
https://ubuntu.com/security/notices/USN-6747-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-6747-1.json
Related
  • CVE-2024-3302
  • CVE-2024-3852
  • CVE-2024-3853
  • CVE-2024-3854
  • CVE-2024-3855
  • CVE-2024-3856
  • CVE-2024-3857
  • CVE-2024-3858
  • CVE-2024-3859
  • CVE-2024-3860
  • CVE-2024-3861
  • CVE-2024-3862
  • CVE-2024-3864
  • CVE-2024-3865
Published
2024-04-24T04:43:24.811219Z
Modified
2024-04-24T04:43:24.811219Z
Summary
firefox vulnerabilities
Details

Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2024-3852, CVE-2024-3864, CVE-2024-3865)

Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2 CONTINUATION frames. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-3302)

Gary Kwong discovered that Firefox did not properly manage memory when running garbage collection during realm initialization. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-3853)

Lukas Bernhard discovered that Firefox did not properly manage memory during JIT optimisations, leading to an out-of-bounds read vulnerability. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2024-3854, CVE-2024-3855)

Nan Wang discovered that Firefox did not properly manage memory during WASM garbage collection. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-3856)

Lukas Bernhard discovered that Firefox did not properly manage memory when handling JIT created code during garbage collection. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-3857)

Lukas Bernhard discovered that Firefox did not properly manage memory when tracing in JIT. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-3858)

Ronald Crane discovered that Firefox did not properly manage memory in the OpenType sanitizer on 32-bit devices, leading to an out-of-bounds read vulnerability. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2024-3859)

Garry Kwong discovered that Firefox did not properly manage memory when tracing empty shape lists in JIT. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-3860)

Ronald Crane discovered that Firefox did not properly manage memory when handling an AlignedBuffer. An attacker could potentially exploit this issue to cause denial of service, or execute arbitrary code. (CVE-2024-3861)

Ronald Crane discovered that Firefox did not properly manage memory when handling code in MarkStack. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-3862)

References

Affected packages

Ubuntu:20.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
125.0.2+build1-0ubuntu0.20.04.2

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-de": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-nl": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-kn": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-gl": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-fy": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-eo": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-km": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-or": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-az": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-lt": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-hy": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-kk": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-sv": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-uk": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-sr": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ca": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-is": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ne": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ga": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-it": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ja": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-lg": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ms": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-dev": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ia": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ko": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-hr": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-mai": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-nb": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-mozsymbols": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-vi": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-zh-hans": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-he": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-sw": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-el": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-oc": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-xh": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-tg": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-nn": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-csb": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ar": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-cs": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-gn": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-hsb": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-zu": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-my": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ro": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-geckodriver": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-szl": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-af": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-sk": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-nso": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-si": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-cy": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-fa": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-cak": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-sq": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-en": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-tr": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-br": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-et": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ast": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-th": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-da": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-fi": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ku": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-mn": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ru": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-mk": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-bg": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-hu": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-gu": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-bn": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-kab": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ml": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-an": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-be": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-eu": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-fr": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-pa": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-as": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-id": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-mr": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-bs": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-te": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-lv": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ka": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ta": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-gd": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-zh-hant": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-uz": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-hi": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-es": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-ur": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-pl": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-pt": "125.0.2+build1-0ubuntu0.20.04.2",
            "firefox-locale-sl": "125.0.2+build1-0ubuntu0.20.04.2"
        }
    ]
}