Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 941224 (CVE-2024-9680, MFSA2024-51) - <www-client/firefox{-bin,}-{115.16.1,128.3.1,131.0.2} - Use after free in animation timeline
Summary: <www-client/firefox{-bin,}-{115.16.1,128.3.1,131.0.2} - Use after free in ani...
Status: RESOLVED FIXED
Alias: CVE-2024-9680, MFSA2024-51
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://www.mozilla.org/en-US/securit...
Whiteboard: A2 [glsa+]
Keywords:
: 941232 (view as bug list)
Depends on: 940714 941273
Blocks:
  Show dependency tree
 
Reported: 2024-10-10 02:36 UTC by snow flurry
Modified: 2024-12-07 10:11 UTC (History)
9 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description snow flurry 2024-10-10 02:36:51 UTC
From MFSA 2024-51:

CVE-2024-9680: Use-after-free in Animation timeline

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2024-10-10 11:01:20 UTC
*** Bug 941232 has been marked as a duplicate of this bug. ***
Comment 3 Larry the Git Cow gentoo-dev 2024-12-07 10:09:52 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=2b9f72d9064dacc77713003b6c6bda8dce701645

commit 2b9f72d9064dacc77713003b6c6bda8dce701645
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-12-07 10:09:25 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-12-07 10:09:35 +0000

    [ GLSA 202412-04 ] Mozilla Firefox: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/936215
    Bug: https://bugs.gentoo.org/937467
    Bug: https://bugs.gentoo.org/941169
    Bug: https://bugs.gentoo.org/941174
    Bug: https://bugs.gentoo.org/941224
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202412-04.xml | 129 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 129 insertions(+)