CVE-2024-3859Out-of-bounds Read in Mozilla Firefox

Severity
5.9MEDIUMNVD
EPSS
1.7%
top 17.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateApr 25

Description

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:NExploitability: 1.6 | Impact: 4.2

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified125
NVDmozilla/firefox< 115.10+1
CVEListV5mozilla/firefox_esrunspecified115.10
CVEListV5mozilla/thunderbirdunspecified115.10
NVDmozilla/thunderbird< 115.10

Also affects: Debian Linux 10.0

🔴Vulnerability Details

3
OSV
CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font2024-04-16
GHSA
GHSA-6f82-r7wj-8fxf: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font2024-04-16
CVEList
CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font2024-04-16

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2024-04-25
Ubuntu
Firefox vulnerabilities2024-04-24
Red Hat
Mozilla: Integer-overflow led to out-of-bounds-read in the OpenType sanitizer2024-04-16
Debian
CVE-2024-3859: firefox - On 32-bit versions there were integer-overflows that led to an out-of-bounds-rea...2024
Mozilla
Mozilla Foundation Security Advisory 2024-18: CVE-2024-3859
CVE-2024-3859 — Out-of-bounds Read in Mozilla Firefox | cvebase