CVE-2024-8394Use After Free in Mozilla Thunderbird

CWE-416Use After Free8 documents8 sources
Severity
6.5MEDIUMNVD
EPSS
0.4%
top 41.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 6

Description

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5mozilla/thunderbirdunspecified128.2
NVDmozilla/thunderbird< 128.2.0
Debianmozilla/thunderbird< 1:128.2.0esr-1+1

🔴Vulnerability Details

3
OSV
CVE-2024-8394: When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash2024-09-06
CVEList
CVE-2024-8394: When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash2024-09-06
GHSA
GHSA-688v-74jq-v222: When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash2024-09-06

📋Vendor Advisories

3
Red Hat
thunderbird: Crash when aborting verification of OTR chat2024-09-06
Debian
CVE-2024-8394: thunderbird - When aborting the verification of an OTR chat session, an attacker could have ca...2024
Mozilla
Mozilla Foundation Security Advisory 2024-43: CVE-2024-8394

💬Community

1
Bugzilla
CVE-2024-26875 kernel: media: pvrusb2: fix uaf in pvr2_context_set_notify2024-04-17
CVE-2024-8394 — Use After Free in Mozilla Thunderbird | cvebase