CVE-2024-6614Infinite Loop in Mozilla Firefox

CWE-835Infinite Loop10 documents8 sources
Severity
4.3MEDIUMNVD
OSV4.7
EPSS
0.2%
top 56.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateJul 10

Description

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified128
NVDmozilla/firefox< 128.0
CVEListV5mozilla/thunderbirdunspecified128
NVDmozilla/thunderbird< 128.0
Ubuntumozilla/firefox< 128.0+build2-0ubuntu0.20.04.1

🔴Vulnerability Details

4
OSV
firefox vulnerabilities2024-07-10
OSV
CVE-2024-6614: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces2024-07-10
GHSA
GHSA-h7q8-vff8-p3j8: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces2024-07-09
CVEList
Incorrect listing of stack frames2024-07-09

📋Vendor Advisories

5
Ubuntu
Firefox vulnerabilities2024-07-10
Microsoft
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.2024-07-09
Debian
CVE-2024-6614: firefox - The frame iterator could get stuck in a loop when encountering certain wasm fram...2024
Mozilla
Mozilla Foundation Security Advisory 2024-29: CVE-2024-6614
Mozilla
Mozilla Foundation Security Advisory 2024-32: CVE-2024-6614
CVE-2024-6614 — Infinite Loop in Mozilla Firefox | cvebase