CERT-In Vulnerability Note
CIVN-2024-0101
Multiple Vulnerabilities in Mozilla Firefox
Original Issue Date:April 03, 2024
Severity Rating: HIGH
Software Affected
- Mozilla Firefox versions prior to 124.0.1
- Mozilla Firefox ESR versions prior to 115.9.1
Overview
Multiple vulnerabilities have been reported in Mozilla Firefox which could be exploited by a remote attacker to perform execute arbitrary code or cause denial of service condition on the targeted system.
Description
These vulnerabilities exist in Mozilla Firefox due to Out-of-bounds access via Range Analysis bypass and Privileged JavaScript Execution via Event Handlers. A remote attacker could exploit these vulnerabilities by persuading a victim to visit specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to perform execute arbitrary code or cause denial of service condition on the targeted system.
Solution
Apply appropriate updates fixes as mentioned in Mozilla Security advisories:
https://www.mozilla.org/en-US/security/advisories/mfsa2024-15/
https://www.mozilla.org/en-US/security/advisories/mfsa2024-16/#CVE-2024-29944
Vendor Information
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2024-15/
https://www.mozilla.org/en-US/security/advisories/mfsa2024-16/#CVE-2024-29944
References
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2024-15/
https://www.mozilla.org/en-US/security/advisories/mfsa2024-16/#CVE-2024-29944
CVE Name
CVE-2024-29943
CVE-2024-29944
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|