Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 936215 (CVE-2024-6606, CVE-2024-6607, CVE-2024-6608, CVE-2024-6609, CVE-2024-6610, CVE-2024-6611, CVE-2024-6612, CVE-2024-6613, CVE-2024-6614, CVE-2024-6615)

Summary: <www-client/firefox{-bin,}-{115.13.0,128.0}: Multiple vulnerabilities
Product: Gentoo Security Reporter: Christopher Fore <csfore>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: normal CC: mozilla
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.mozilla.org/en-US/security/advisories/mfsa2024-29/
Whiteboard: A3 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 936214    

Description Christopher Fore 2024-07-17 12:48:34 UTC
The following CVEs only affect Firefox <128:


CVE-2024-6606:

Clipboard code failed to check the index on an array access. This could have lead to an out-of-bounds read.


CVE-2024-6607:

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a <select> element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions.


CVE-2024-6608:

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window.


CVE-2024-6609:

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again.


CVE-2024-6610:

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode.


CVE-2024-6611:

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies.


CVE-2024-6612:

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened.


CVE-2024-6613:

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces.


CVE-2024-6614:

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces.


CVE-2024-6615:

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.


Please refer to the tracker for the CVEs that affect all Mozilla products.
Comment 1 Joonas Niilola gentoo-dev 2024-10-09 07:17:48 UTC
Tree is clean for these versions.