CVE-2024-1546Out-of-bounds Read in Mozilla Firefox

Severity
7.5HIGHNVD
EPSS
0.5%
top 34.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMar 6

Description

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified123
NVDmozilla/firefox< 115.8.0+1
CVEListV5mozilla/firefox_esrunspecified115.8
CVEListV5mozilla/thunderbirdunspecified115.8
NVDmozilla/thunderbird< 115.8.0

Also affects: Debian Linux 10.0

🔴Vulnerability Details

6
OSV
firefox regressions2024-03-06
GHSA
JSONata expression can pollute the "Object" prototype2024-03-04
OSV
firefox vulnerabilities2024-02-22
CVEList
CVE-2024-1546: When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read2024-02-20
GHSA
GHSA-w267-2gcr-ggcp: When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read2024-02-20

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2024-03-04
Ubuntu
Firefox vulnerabilities2024-02-22
Red Hat
Mozilla: Out-of-bounds memory read in networking channels2024-02-20
Debian
CVE-2024-1546: firefox - When storing and re-accessing data on a networking channel, the length of buffer...2024
Mozilla
Mozilla Foundation Security Advisory 2024-06: CVE-2024-1546
CVE-2024-1546 — Out-of-bounds Read in Mozilla Firefox | cvebase