Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 936215 (CVE-2024-6606, CVE-2024-6607, CVE-2024-6608, CVE-2024-6609, CVE-2024-6610, CVE-2024-6611, CVE-2024-6612, CVE-2024-6613, CVE-2024-6614, CVE-2024-6615) - <www-client/firefox{-bin,}-{115.13.0,128.0}: Multiple vulnerabilities
Summary: <www-client/firefox{-bin,}-{115.13.0,128.0}: Multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2024-6606, CVE-2024-6607, CVE-2024-6608, CVE-2024-6609, CVE-2024-6610, CVE-2024-6611, CVE-2024-6612, CVE-2024-6613, CVE-2024-6614, CVE-2024-6615
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://www.mozilla.org/en-US/securit...
Whiteboard: A3 [glsa]
Keywords:
Depends on:
Blocks: CVE-2024-6601, CVE-2024-6602, CVE-2024-6603, CVE-2024-6604, MFSA2024-29, MFSA2024-30, MFSA2024-31
  Show dependency tree
 
Reported: 2024-07-17 12:48 UTC by Christopher Fore
Modified: 2024-10-04 07:30 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Fore 2024-07-17 12:48:34 UTC
The following CVEs only affect Firefox <128:


CVE-2024-6606:

Clipboard code failed to check the index on an array access. This could have lead to an out-of-bounds read.


CVE-2024-6607:

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a <select> element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions.


CVE-2024-6608:

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window.


CVE-2024-6609:

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again.


CVE-2024-6610:

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode.


CVE-2024-6611:

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies.


CVE-2024-6612:

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened.


CVE-2024-6613:

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces.


CVE-2024-6614:

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces.


CVE-2024-6615:

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.


Please refer to the tracker for the CVEs that affect all Mozilla products.