Skip to main content

Mozilla Releases Security Updates for Firefox and Firefox ESR

Advisory addresses 16 vulnerabilities, including two rated as high severity

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Advisory addresses 16 vulnerabilities, including two rated as high severity


Threat details

Introduction

Mozilla has released security updates to address 16 vulnerabilities in Firefox and Firefox ESR, with two of the vulnerabilities rated as high.

  • CVE-2024-4764: Use-after-free when audio input connected with multiple consumers
  • CVE-2024-4367: A type check was missing when handling fonts in PDF.js. Successful exploitation of this vulnerability could allow for arbitrary code execution in the context of the logged on user.

Nine medium-severity and five low severity vulnerabilities were also addressed. 

Mozilla PDF.js could allow for arbitrary code execution (CVE-2024-4367)

The Center for Internet Security (CIS) released an advisory about this vulnerability, which states that successful exploitation of this vulnerability could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users that are configured to have fewer rights on the system could be less impacted than those that operate with administrative user rights.

CVE-2024-4367 applies to Mozilla PDF.js, a PDF viewer built in to Mozilla Firefox but that can also be used by other browsers. Other affected browsers will have to be updated separately to remediate the vulnerability. 

CIS states there is currently no known exploitation.

Update: CVE-2024-4367, the arbitrary JavaScript execution in PDF.js vulnerability is also present in Mozilla Thunderbird. 

Proof-of-concept exploit code has been published for CVE-2024-4367

A blog with proof-of-concept (PoC) code has been published for CVE-2024-4367. Exploitation of this vulnerability is considered more likely.


Threat updates

Date Update
22 May 2024 Proof-of-concept exploit code has been published for CVE-2024-4367

This cyber alert was updated to reflect this change.

15 May 2024 Security vulnerabilities fixed in Thunderbird 115.11

CVE-2024-4367: Arbitrary JavaScript execution in PDF.js is also present in Mozilla Thunderbird. A new advisory has been added to the remediation steps below.


Remediation advice

Affected organisations are encouraged to review the Mozilla Foundation Security Advisories and apply the relevant updates from the advisories below.


Remediation steps

Type Step
Patch

Security Advisory 2024-21

Security Vulnerabilities fixed in Firefox 126


https://www.mozilla.org/en-US/security/advisories/mfsa2024-21/
Patch

Security Advisory 2024-22 

Security Vulnerabilities fixed in Firefox ESR 115.11


https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/

Security Advisory 2024-23

Security Vulnerabilities fixed in Thunderbird 115.11


https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/


Last edited: 22 May 2024 5:14 pm