Mozilla Releases Security Updates for Firefox and Firefox ESR
Advisory addresses 16 vulnerabilities, including two rated as high severity
Summary
Advisory addresses 16 vulnerabilities, including two rated as high severity
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Mozilla has released security updates to address 16 vulnerabilities in Firefox and Firefox ESR, with two of the vulnerabilities rated as high.
- CVE-2024-4764: Use-after-free when audio input connected with multiple consumers
- CVE-2024-4367: A type check was missing when handling fonts in PDF.js. Successful exploitation of this vulnerability could allow for arbitrary code execution in the context of the logged on user.
Nine medium-severity and five low severity vulnerabilities were also addressed.
Mozilla PDF.js could allow for arbitrary code execution (CVE-2024-4367)
The Center for Internet Security (CIS) released an advisory about this vulnerability, which states that successful exploitation of this vulnerability could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users that are configured to have fewer rights on the system could be less impacted than those that operate with administrative user rights.
CVE-2024-4367 applies to Mozilla PDF.js, a PDF viewer built in to Mozilla Firefox but that can also be used by other browsers. Other affected browsers will have to be updated separately to remediate the vulnerability.
CIS states there is currently no known exploitation.
Update: CVE-2024-4367, the arbitrary JavaScript execution in PDF.js vulnerability is also present in Mozilla Thunderbird.
Proof-of-concept exploit code has been published for CVE-2024-4367
A blog with proof-of-concept (PoC) code has been published for CVE-2024-4367. Exploitation of this vulnerability is considered more likely.
Threat updates
| Date | Update |
|---|---|
| 22 May 2024 |
Proof-of-concept exploit code has been published for CVE-2024-4367
This cyber alert was updated to reflect this change. |
| 15 May 2024 |
Security vulnerabilities fixed in Thunderbird 115.11
CVE-2024-4367: Arbitrary JavaScript execution in PDF.js is also present in Mozilla Thunderbird. A new advisory has been added to the remediation steps below. |
Remediation advice
Affected organisations are encouraged to review the Mozilla Foundation Security Advisories and apply the relevant updates from the advisories below.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Security Advisory 2024-21 Security Vulnerabilities fixed in Firefox 126 https://www.mozilla.org/en-US/security/advisories/mfsa2024-21/ |
| Patch |
Security Advisory 2024-22 Security Vulnerabilities fixed in Firefox ESR 115.11 https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/ |
|
Security Advisory 2024-23 Security Vulnerabilities fixed in Thunderbird 115.11 https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ |
Definitive source of threat updates
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-21/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/
- https://www.cisecurity.org/advisory/a-vulnerability-in-mozilla-pdfjs-could-allow-for-arbitrary-code-execution_2024-046
CVE Vulnerabilities
Last edited: 22 May 2024 5:14 pm