UBUNTU-CVE-2024-10467

See a problem?
Source
https://ubuntu.com/security/CVE-2024-10467
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-10467.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-10467
Related
Published
2024-10-29T13:15:00Z
Modified
2024-10-30T16:30:59Z
Summary
[none]
Details

Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

References

Affected packages

Ubuntu:Pro:18.04:LTS / mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*

52.3.1-0ubuntu3
52.3.1-7fakesync1
52.8.1-0ubuntu0.18.04.1
52.9.1-0ubuntu0.18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / mozjs38

Package

Name
mozjs38
Purl
pkg:deb/ubuntu/mozjs38?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

38.*

38.8.0~repack1-0ubuntu1
38.8.0~repack1-0ubuntu3
38.8.0~repack1-0ubuntu4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / firefox

Package

Name
firefox
Purl
pkg:deb/ubuntu/firefox?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

69.*

69.0.3+build1-0ubuntu1

70.*

70.0+build2-0ubuntu1
70.0+build2-0ubuntu2
70.0.1+build1-0ubuntu2

71.*

71.0+build2-0ubuntu2
71.0+build5-0ubuntu1

72.*

72.0.1+build1-0ubuntu1
72.0.2+build1-0ubuntu1

73.*

73.0+build1-0ubuntu1
73.0+build2-0ubuntu1
73.0+build3-0ubuntu1
73.0.1+build1-0ubuntu1

74.*

74.0+build1-0ubuntu1
74.0+build2-0ubuntu1
74.0+build2-0ubuntu2
74.0+build3-0ubuntu1

75.*

75.0+build3-0ubuntu1

76.*

76.0+build2-0ubuntu0.20.04.1
76.0.1+build1-0ubuntu0.20.04.1

77.*

77.0.1+build1-0ubuntu0.20.04.1

78.*

78.0.1+build1-0ubuntu0.20.04.1
78.0.2+build2-0ubuntu0.20.04.1

79.*

79.0+build1-0ubuntu0.20.04.1

80.*

80.0+build2-0ubuntu0.20.04.1
80.0.1+build1-0ubuntu0.20.04.1

81.*

81.0+build2-0ubuntu0.20.04.1
81.0.2+build1-0ubuntu0.20.04.1

82.*

82.0+build2-0ubuntu0.20.04.1
82.0.2+build1-0ubuntu0.20.04.1
82.0.3+build1-0ubuntu0.20.04.1

83.*

83.0+build2-0ubuntu0.20.04.1

84.*

84.0+build3-0ubuntu0.20.04.1
84.0.1+build1-0ubuntu0.20.04.1
84.0.2+build1-0ubuntu0.20.04.1

85.*

85.0+build1-0ubuntu0.20.04.1
85.0.1+build1-0ubuntu0.20.04.1

86.*

86.0+build3-0ubuntu0.20.04.1
86.0.1+build1-0ubuntu0.20.04.1

87.*

87.0+build3-0ubuntu0.20.04.2

88.*

88.0+build2-0ubuntu0.20.04.1
88.0.1+build1-0ubuntu0.20.04.2

89.*

89.0+build2-0ubuntu0.20.04.2
89.0.1+build1-0ubuntu0.20.04.1
89.0.2+build1-0ubuntu0.20.04.1

90.*

90.0+build1-0ubuntu0.20.04.1
90.0.2+build1-0ubuntu0.20.04.1

91.*

91.0+build2-0ubuntu0.20.04.1
91.0.1+build1-0ubuntu0.20.04.1
91.0.2+build1-0ubuntu0.20.04.1

92.*

92.0+build3-0ubuntu0.20.04.1

93.*

93.0+build1-0ubuntu0.20.04.1

94.*

94.0+build3-0ubuntu0.20.04.1

95.*

95.0+build1-0ubuntu0.20.04.1
95.0.1+build2-0ubuntu0.20.04.1

96.*

96.0+build2-0ubuntu0.20.04.1

97.*

97.0+build2-0ubuntu0.20.04.1
97.0.2+build1-0ubuntu0.20.04.1

98.*

98.0+build3-0ubuntu0.20.04.2
98.0.1+build2-0ubuntu0.20.04.1
98.0.2+build1-0ubuntu0.20.04.1

99.*

99.0+build2-0ubuntu0.20.04.2

100.*

100.0+build2-0ubuntu0.20.04.1
100.0.2+build1-0ubuntu0.20.04.1

101.*

101.0.1+build1-0ubuntu0.20.04.1

102.*

102.0+build2-0ubuntu0.20.04.1

103.*

103.0+build1-0ubuntu0.20.04.1

104.*

104.0+build3-0ubuntu0.20.04.1

105.*

105.0+build2-0ubuntu0.20.04.1

106.*

106.0.2+build1-0ubuntu0.20.04.1
106.0.5+build1-0ubuntu0.20.04.1

107.*

107.0+build2-0ubuntu0.20.04.1

108.*

108.0+build2-0ubuntu0.20.04.1
108.0.1+build1-0ubuntu0.20.04.1
108.0.2+build1-0ubuntu0.20.04.1

109.*

109.0+build2-0ubuntu0.20.04.1
109.0.1+build1-0ubuntu0.20.04.2

110.*

110.0+build3-0ubuntu0.20.04.1
110.0.1+build2-0ubuntu0.20.04.1

111.*

111.0+build2-0ubuntu0.20.04.1
111.0.1+build2-0ubuntu0.20.04.1

112.*

112.0+build2-0ubuntu0.20.04.1
112.0.1+build1-0ubuntu0.20.04.1
112.0.2+build1-0ubuntu0.20.04.1

113.*

113.0+build2-0ubuntu0.20.04.1
113.0.1+build1-0ubuntu0.20.04.1
113.0.2+build1-0ubuntu0.20.04.1

114.*

114.0+build3-0ubuntu0.20.04.1
114.0.1+build1-0ubuntu0.20.04.1
114.0.2+build1-0ubuntu0.20.04.1

115.*

115.0+build2-0ubuntu0.20.04.3
115.0.2+build1-0ubuntu0.20.04.1

116.*

116.0+build2-0ubuntu0.20.04.2
116.0.2+build1-0ubuntu0.20.04.1
116.0.3+build2-0ubuntu0.20.04.1

117.*

117.0+build2-0ubuntu0.20.04.1
117.0.1+build2-0ubuntu0.20.04.1

118.*

118.0.1+build1-0ubuntu0.20.04.1
118.0.2+build2-0ubuntu0.20.04.1

119.*

119.0+build2-0ubuntu0.20.04.1
119.0.1+build1-0ubuntu0.20.04.1

120.*

120.0+build2-0ubuntu0.20.04.1
120.0.1+build1-0ubuntu0.20.04.1

121.*

121.0+build1-0ubuntu0.20.04.1
121.0.1+build1-0ubuntu0.20.04.1

122.*

122.0+build2-0ubuntu0.20.04.1
122.0.1+build1-0ubuntu0.20.04.1

123.*

123.0+build3-0ubuntu0.20.04.1
123.0.1+build1-0ubuntu0.20.04.1

124.*

124.0+build1-0ubuntu0.20.04.1
124.0.1+build1-0ubuntu0.20.04.1
124.0.2+build1-0ubuntu0.20.04.1

125.*

125.0.2+build1-0ubuntu0.20.04.2
125.0.3+build1-0ubuntu0.20.04.1

126.*

126.0+build2-0ubuntu0.20.04.1
126.0.1+build1-0ubuntu0.20.04.1

127.*

127.0.2+build1-0ubuntu0.20.04.1

128.*

128.0+build2-0ubuntu0.20.04.1

129.*

129.0.1+build1-0ubuntu0.20.04.1
129.0.2+build1-0ubuntu0.20.04.1

130.*

130.0+build2-0ubuntu0.20.04.1
130.0.1+build1-0ubuntu0.20.04.1

131.*

131.0+build1.1-0ubuntu0.20.04.1
131.0.2+build1-0ubuntu0.20.04.1
131.0.3+build1-0ubuntu0.20.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*

52.9.1-1build1
52.9.1-1ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mozjs68

Package

Name
mozjs68
Purl
pkg:deb/ubuntu/mozjs68?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

68.*

68.5.0-1~fakesync
68.5.0-2~fakesync
68.6.0-1
68.6.0-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/ubuntu/thunderbird?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:68.*

1:68.1.2+build1-0ubuntu1
1:68.1.2+build1-0ubuntu2
1:68.2.1+build1-0ubuntu1
1:68.2.2+build1-0ubuntu1
1:68.3.0+build2-0ubuntu1
1:68.3.1+build1-0ubuntu2
1:68.4.1+build1-0ubuntu1
1:68.4.2+build2-0ubuntu1
1:68.5.0+build1-0ubuntu1
1:68.6.0+build2-0ubuntu1
1:68.7.0+build1-0ubuntu1
1:68.7.0+build1-0ubuntu2
1:68.8.0+build2-0ubuntu0.20.04.2
1:68.10.0+build1-0ubuntu0.20.04.1

1:78.*

1:78.7.1+build1-0ubuntu0.20.04.1
1:78.8.1+build1-0ubuntu0.20.04.1
1:78.11.0+build1-0ubuntu0.20.04.2
1:78.13.0+build1-0ubuntu0.20.04.2
1:78.14.0+build1-0ubuntu0.20.04.1
1:78.14.0+build1-0ubuntu0.20.04.2

1:91.*

1:91.5.0+build1-0ubuntu0.20.04.1
1:91.7.0+build2-0ubuntu0.20.04.1
1:91.8.1+build1-0ubuntu0.20.04.1
1:91.9.1+build1-0ubuntu0.20.04.1
1:91.11.0+build2-0ubuntu0.20.04.1

1:102.*

1:102.2.2+build1-0ubuntu0.20.04.1
1:102.4.2+build2-0ubuntu0.20.04.1
1:102.7.1+build2-0ubuntu0.20.04.1
1:102.8.0+build2-0ubuntu0.20.04.1
1:102.9.0+build1-0ubuntu0.20.04.1
1:102.10.0+build2-0ubuntu0.20.04.1
1:102.11.0+build1-0ubuntu0.20.04.1
1:102.13.0+build1-0ubuntu0.20.04.1
1:102.15.0+build1-0ubuntu0.20.04.1
1:102.15.1+build1-0ubuntu0.20.04.1

1:115.*

1:115.3.1+build1-0ubuntu0.20.04.1
1:115.4.1+build1-0ubuntu0.20.04.1
1:115.5.0+build1-0ubuntu0.20.04.1
1:115.6.0+build2-0ubuntu0.20.04.1
1:115.8.1+build1-0ubuntu0.20.04.1
1:115.9.0+build1-0ubuntu0.20.04.1
1:115.10.1+build1-0ubuntu0.20.04.1
1:115.11.0+build2-0ubuntu0.20.04.1
1:115.12.0+build3-0ubuntu0.20.04.1
1:115.13.0+build5-0ubuntu0.20.04.1
1:115.15.0+build1-0ubuntu0.20.04.1
1:115.16.0+build2-0ubuntu0.20.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mozjs102

Package

Name
mozjs102
Purl
pkg:deb/ubuntu/mozjs102?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

102.*

102.11.0-0ubuntu0.22.04.1
102.12.0-0ubuntu0.22.04.1
102.13.0-0ubuntu0.22.04.1
102.15.1-0ubuntu0.22.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mozjs78

Package

Name
mozjs78
Purl
pkg:deb/ubuntu/mozjs78?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

78.*

78.13.0-1
78.15.0-2
78.15.0-4ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mozjs91

Package

Name
mozjs91
Purl
pkg:deb/ubuntu/mozjs91?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

91.*

91.5.1-0ubuntu1
91.6.0-1
91.6.0-2
91.7.0-2
91.10.0-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/ubuntu/thunderbird?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:91.*

1:91.1.2+build1-0ubuntu1
1:91.3.0+build2-0ubuntu1
1:91.3.1+build1-0ubuntu1
1:91.3.2+build1-0ubuntu1
1:91.4.0+build1.1-0ubuntu1
1:91.4.0+build2-0ubuntu1
1:91.5.0+build1-0ubuntu1
1:91.5.1+build1-0ubuntu1
1:91.6.1+build1-0ubuntu1
1:91.7.0+build1-0ubuntu1
1:91.7.0+build2-0ubuntu1
1:91.8.0+build2-0ubuntu1
1:91.9.1+build1-0ubuntu0.22.04.1
1:91.11.0+build2-0ubuntu0.22.04.1

1:102.*

1:102.2.2+build1-0ubuntu0.22.04.1
1:102.4.2+build2-0ubuntu0.22.04.1
1:102.7.1+build2-0ubuntu0.22.04.1
1:102.8.0+build2-0ubuntu0.22.04.1
1:102.9.0+build1-0ubuntu0.22.04.1
1:102.10.0+build2-0ubuntu0.22.04.1
1:102.11.0+build1-0ubuntu0.22.04.1
1:102.13.0+build1-0ubuntu0.22.04.1
1:102.15.0+build1-0ubuntu0.22.04.1
1:102.15.1+build1-0ubuntu0.22.04.1

1:115.*

1:115.3.1+build1-0ubuntu0.22.04.2
1:115.4.1+build1-0ubuntu0.22.04.1
1:115.5.0+build1-0ubuntu0.22.04.1
1:115.6.0+build2-0ubuntu0.22.04.1
1:115.8.1+build1-0ubuntu0.22.04.1
1:115.9.0+build1-0ubuntu0.22.04.1
1:115.10.1+build1-0ubuntu0.22.04.1
1:115.11.0+build2-0ubuntu0.22.04.1
1:115.12.0+build3-0ubuntu0.22.04.1
1:115.13.0+build5-0ubuntu0.22.04.1
1:115.15.0+build1-0ubuntu0.22.04.1
1:115.16.0+build2-0ubuntu0.22.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / mozjs115

Package

Name
mozjs115
Purl
pkg:deb/ubuntu/mozjs115?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

115.*

115.10.0-1
115.11.0-1
115.12.0-1
115.12.0-1build1
115.13.0-1
115.14.0-1
115.16.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / mozjs102

Package

Name
mozjs102
Purl
pkg:deb/ubuntu/mozjs102?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

102.*

102.15.1-1
102.15.1-3ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / mozjs115

Package

Name
mozjs115
Purl
pkg:deb/ubuntu/mozjs115?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

115.*

115.3.0-0ubuntu1
115.4.0-2
115.5.0-1
115.6.0-1
115.7.0-4
115.8.0-1
115.9.0-1
115.9.0-1build1
115.10.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}