CVE-2024-4778
Published: 14 May 2024
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.
Notes
| Author | Note |
|---|---|
| tyhicks | mozjs contains a copy of the SpiderMonkey JavaScript engine |
| mdeslaur | starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap starting with Ubuntu 24.04, the thunderbird package is just a script that installs the Thunderbird snap |
Priority
Status
| Package | Release | Status |
|---|---|---|
|
firefox Launchpad, Ubuntu, Debian |
focal |
Released
(126.0+build2-0ubuntu0.20.04.1)
|
| jammy |
Not vulnerable
(code not present)
|
|
| mantic |
Not vulnerable
(code not present)
|
|
| noble |
Not vulnerable
(code not present)
|
|
| upstream |
Needs triage
|
|
|
mozjs102 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
| jammy |
Ignored
|
|
| mantic |
Ignored
(end of life, was needs-triage)
|
|
| noble |
Ignored
|
|
| upstream |
Ignored
|
|
|
mozjs38 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
| focal |
Does not exist
|
|
| jammy |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs52 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
| focal |
Ignored
|
|
| jammy |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs68 Launchpad, Ubuntu, Debian |
focal |
Ignored
|
| jammy |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs78 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
| jammy |
Ignored
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs91 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
| jammy |
Ignored
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
thunderbird Launchpad, Ubuntu, Debian |
focal |
Not vulnerable
(code not present)
|
| jammy |
Not vulnerable
(code not present)
|
|
| mantic |
Ignored
(end of life, was needed)
|
|
| noble |
Not vulnerable
(code not present)
|
|
| upstream |
Needs triage
|
References
- https://www.cve.org/CVERecord?id=CVE-2024-4778
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-21/#CVE-2024-4778
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1838834%2C1889291%2C1889595%2C1890204%2C1891545
- https://www.mozilla.org/security/advisories/mfsa2024-21/
- https://ubuntu.com/security/notices/USN-6779-1
- NVD
- Launchpad
- Debian