CVE-2024-7652
published 2024-09-06CVE-2024-7652: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 128.0-1 (sid) | firefox 128.0-1 (sid) |
| debian | firefox-esr | < firefox 128.0-1 (sid) | firefox 128.0-1 (sid) |
| debian | thunderbird | < firefox 128.0-1 (sid) | firefox 128.0-1 (sid) |
| mozilla | firefox | < 115.13.0 | 115.13.0 |
| mozilla | firefox | < 128.0 | 128.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 128 | 128 |
| mozilla | firefox_esr | >= unspecified < 115.13 | 115.13 |
| mozilla | thunderbird | < 115.13.0 | 115.13.0 |
| mozilla | thunderbird | >= 0 < 1:115.13.0-1~deb11u1 | 1:115.13.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:115.13.0-1~deb12u1 | 1:115.13.0-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:115.13.0-1 | 1:115.13.0-1 |
| mozilla | thunderbird | >= 0 < 1:115.13.0-1 | 1:115.13.0-1 |
| mozilla | thunderbird | >= 116.0 < 128.0 | 128.0 |
| mozilla | thunderbird | >= unspecified < 115.13 | 115.13 |
| mozilla | thunderbird | >= unspecified < 128 | 128 |
| tc39 | ecma262 | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv7.5HIGH
Red Hat
mozilla: Type Confusion in Async Generators in Javascript Engine
vendor_redhat·2024-09-06·CVSS 7.5
CVE-2024-7652 [HIGH] CWE-843 mozilla: Type Confusion in Async Generators in Javascript Engine
mozilla: Type Confusion in Async Generators in Javascript Engine
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as follows: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Mitigation: Mitigation for this issue is
Debian
CVE-2024-7652: firefox - An error in the ECMA-262 specification relating to Async Generators could have r...
vendor_debian·2024·CVSS 7.5
CVE-2024-7652 [HIGH] CVE-2024-7652: firefox - An error in the ECMA-262 specification relating to Async Generators could have r...
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
Mozilla
Mozilla Foundation Security Advisory 2024-31: CVE-2024-7652
vendor_mozilla·CVSS 7.5
CVE-2024-7652 [HIGH] Mozilla Foundation Security Advisory 2024-31: CVE-2024-7652
Mozilla Foundation Security Advisory 2024-31
CVE: CVE-2024-7652
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 115.13
Mozilla
Mozilla Foundation Security Advisory 2024-30: CVE-2024-7652
vendor_mozilla·CVSS 7.5
CVE-2024-7652 [HIGH] Mozilla Foundation Security Advisory 2024-30: CVE-2024-7652
Mozilla Foundation Security Advisory 2024-30
CVE: CVE-2024-7652
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.13
Mozilla
Mozilla Foundation Security Advisory 2024-32: CVE-2024-7652
vendor_mozilla·CVSS 7.5
CVE-2024-7652 [HIGH] Mozilla Foundation Security Advisory 2024-32: CVE-2024-7652
Mozilla Foundation Security Advisory 2024-32
CVE: CVE-2024-7652
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 128
Mozilla
Mozilla Foundation Security Advisory 2024-29: CVE-2024-7652
vendor_mozilla·CVSS 7.5
CVE-2024-7652 [HIGH] Mozilla Foundation Security Advisory 2024-29: CVE-2024-7652
Mozilla Foundation Security Advisory 2024-29
CVE: CVE-2024-7652
Product: Firefox
Impact: high
Fixed in: Firefox 128
OSV
CVE-2024-7652: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption
osv·2024-09-06·CVSS 7.5
CVE-2024-7652 [HIGH] CVE-2024-7652: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
GHSA
GHSA-crg5-c758-hm56: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption
ghsa_unreviewed·2024-09-06
CVE-2024-7652 [HIGH] CWE-476 GHSA-crg5-c758-hm56: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1901411https://github.com/tc39/ecma262/security/advisories/GHSA-g38c-wh3c-5h9rhttps://www.mozilla.org/security/advisories/mfsa2024-29/https://www.mozilla.org/security/advisories/mfsa2024-30/https://www.mozilla.org/security/advisories/mfsa2024-31/https://www.mozilla.org/security/advisories/mfsa2024-32/
2024-09-06
Published