CVE-2024-6608
Published: 10 July 2024
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Notes
| Author | Note |
|---|---|
| tyhicks | mozjs contains a copy of the SpiderMonkey JavaScript engine |
| mdeslaur | starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap starting with Ubuntu 24.04, the thunderbird package is just a script that installs the Thunderbird snap |
Priority
Status
| Package | Release | Status |
|---|---|---|
|
firefox Launchpad, Ubuntu, Debian |
focal |
Released
(128.0+build2-0ubuntu0.20.04.1)
|
| jammy |
Not vulnerable
(code not present)
|
|
| mantic |
Not vulnerable
(code not present)
|
|
| noble |
Not vulnerable
(code not present)
|
|
| upstream |
Needs triage
|
|
|
mozjs102 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
| jammy |
Ignored
|
|
| mantic |
Ignored
(end of life, was needs-triage)
|
|
| noble |
Ignored
|
|
| upstream |
Ignored
|
|
|
mozjs38 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
| focal |
Does not exist
|
|
| jammy |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs52 Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
| focal |
Ignored
|
|
| jammy |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs68 Launchpad, Ubuntu, Debian |
focal |
Ignored
|
| jammy |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs78 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
| jammy |
Ignored
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
mozjs91 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
| jammy |
Ignored
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| upstream |
Ignored
|
|
|
thunderbird Launchpad, Ubuntu, Debian |
focal |
Not vulnerable
(code not present)
|
| jammy |
Not vulnerable
(code not present)
|
|
| mantic |
Ignored
(end of life, was needed)
|
|
| noble |
Not vulnerable
(code not present)
|
|
| upstream |
Needs triage
|
References
- https://www.cve.org/CVERecord?id=CVE-2024-6608
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-29/#CVE-2024-6608
- https://bugzilla.mozilla.org/show_bug.cgi?id=1743329
- https://www.mozilla.org/security/advisories/mfsa2024-29/
- https://ubuntu.com/security/notices/USN-6890-1
- NVD
- Launchpad
- Debian