CVE-2024-3859 — Out-of-bounds Read in Mozilla Firefox
Severity
5.9MEDIUMNVD
EPSS
1.7%
top 17.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 16
Latest updateApr 25
Description
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:NExploitability: 1.6 | Impact: 4.2
Affected Packages6 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
3OSV▶
CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font↗2024-04-16
GHSA▶
GHSA-6f82-r7wj-8fxf: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font↗2024-04-16
CVEList▶
CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font↗2024-04-16
📋Vendor Advisories
7Debian▶
CVE-2024-3859: firefox - On 32-bit versions there were integer-overflows that led to an out-of-bounds-rea...↗2024