CVE-2024-6608
Published: 10 July 2024
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Notes
Author | Note |
---|---|
tyhicks |
mozjs contains a copy of the SpiderMonkey JavaScript engine |
mdeslaur |
starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap starting with Ubuntu 24.04, the thunderbird package is just a script that installs the Thunderbird snap |
Priority
Status
Package | Release | Status |
---|---|---|
firefox
Launchpad, Ubuntu, Debian |
focal |
Released
(128.0+build2-0ubuntu0.20.04.1)
|
jammy |
Not vulnerable
(code not present)
|
|
mantic |
Not vulnerable
(code not present)
|
|
noble |
Not vulnerable
(code not present)
|
|
upstream |
Needs triage
|
|
mozjs102
Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
jammy |
Ignored
|
|
mantic |
Ignored
(end of life, was needs-triage)
|
|
noble |
Ignored
|
|
upstream |
Ignored
|
|
mozjs38
Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Ignored
|
|
mozjs52
Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
focal |
Ignored
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Ignored
|
|
mozjs68
Launchpad, Ubuntu, Debian |
focal |
Ignored
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Ignored
|
|
mozjs78
Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
jammy |
Ignored
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Ignored
|
|
mozjs91
Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
jammy |
Ignored
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Ignored
|
|
thunderbird
Launchpad, Ubuntu, Debian |
focal |
Not vulnerable
(code not present)
|
jammy |
Not vulnerable
(code not present)
|
|
mantic |
Ignored
(end of life, was needed)
|
|
noble |
Not vulnerable
(code not present)
|
|
upstream |
Needs triage
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 4.3 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | Low |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
References
- https://www.cve.org/CVERecord?id=CVE-2024-6608
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-29/#CVE-2024-6608
- https://bugzilla.mozilla.org/show_bug.cgi?id=1743329
- https://www.mozilla.org/security/advisories/mfsa2024-29/
- https://ubuntu.com/security/notices/USN-6890-1
- NVD
- Launchpad
- Debian