CVE-2024-3864

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-3864
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-3864.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-3864
Related
Published
2024-04-16T16:15:08Z
Modified
2024-09-11T05:04:17.554590Z
Summary
[none]
Details

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

References

Affected packages

Debian:11 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
115.10.0esr-1~deb11u1

Affected versions

78.*

78.12.0esr-1
78.13.0esr-1~deb9u1
78.13.0esr-1~deb10u1
78.13.0esr-1~deb11u1
78.13.0esr-1
78.14.0esr-1~deb9u1
78.14.0esr-1~deb10u1
78.14.0esr-1~deb11u1
78.14.0esr-1
78.15.0esr-1~deb9u1
78.15.0esr-1~deb10u1
78.15.0esr-1~deb11u1

91.*

91.0esr-1
91.0.1esr-1
91.1.0esr-1
91.2.0esr-1
91.3.0esr-1
91.3.0esr-2
91.4.0esr-1
91.4.1esr-1~deb9u1
91.4.1esr-1~deb11u1
91.5.0esr-1~deb9u1
91.5.0esr-1~deb10u1
91.5.0esr-1~deb11u1
91.5.0esr-1
91.5.1esr-1
91.6.0esr-1~deb9u1
91.6.0esr-1~deb10u1
91.6.0esr-1~deb11u1
91.6.0esr-1
91.6.1esr-1~deb9u1
91.6.1esr-1~deb10u1
91.6.1esr-1~deb11u1
91.6.1esr-1
91.7.0esr-1~deb9u1
91.7.0esr-1~deb10u1
91.7.0esr-1~deb11u1
91.7.0esr-1
91.8.0esr-1~deb9u1
91.8.0esr-1~deb10u1
91.8.0esr-1~deb11u1
91.8.0esr-1
91.9.0esr-1~deb9u1
91.9.0esr-1~deb10u1
91.9.0esr-1~deb11u1
91.9.0esr-1
91.9.1esr-1~deb9u1
91.9.1esr-1~deb10u1
91.9.1esr-1~deb11u1
91.9.1esr-1
91.10.0esr-1~deb9u1
91.10.0esr-1~deb10u1
91.10.0esr-1~deb11u1
91.10.0esr-1
91.11.0esr-1~deb9u1
91.11.0esr-1~deb10u1
91.11.0esr-1~deb11u1
91.11.0esr-1
91.12.0esr-1~deb10u1
91.12.0esr-1~deb11u1
91.12.0esr-1
91.13.0esr-1~deb10u1
91.13.0esr-1~deb11u1

102.*

102.1.0esr-1
102.1.0esr-2
102.2.0esr-1
102.3.0esr-1~deb10u1
102.3.0esr-1~deb10u2
102.3.0esr-1~deb11u1
102.3.0esr-1
102.4.0esr-1~deb10u1
102.4.0esr-1~deb11u1
102.4.0esr-1
102.5.0esr-1~deb10u1
102.5.0esr-1~deb11u1
102.5.0esr-1
102.6.0esr-1~deb10u1
102.6.0esr-1~deb11u1
102.6.0esr-1
102.7.0esr-1~deb10u1
102.7.0esr-1~deb11u1
102.7.0esr-1
102.8.0esr-1~deb10u1
102.8.0esr-1~deb11u1
102.8.0esr-1
102.9.0esr-1~deb10u1
102.9.0esr-1~deb11u1
102.9.0esr-1
102.9.0esr-2
102.10.0esr-1~deb10u1
102.10.0esr-1~deb11u1
102.10.0esr-1
102.11.0esr-1~deb10u1
102.11.0esr-1~deb11u1
102.11.0esr-1
102.12.0esr-1~deb10u1
102.12.0esr-1~deb11u1
102.12.0esr-1~deb12u1
102.12.0esr-1
102.13.0esr-1~deb10u1
102.13.0esr-1~deb11u1
102.13.0esr-1~deb12u1
102.13.0esr-1
102.14.0esr-1~deb10u1
102.14.0esr-1~deb11u1
102.14.0esr-1~deb12u1
102.15.0esr-1~deb10u1
102.15.0esr-1~deb11u1
102.15.0esr-1~deb12u1
102.15.1esr-1~deb10u1
102.15.1esr-1~deb11u1
102.15.1esr-1~deb12u1

115.*

115.0.2esr-1
115.1.0esr-1
115.2.0esr-1
115.2.1esr-1
115.3.0esr-1~deb10u1
115.3.0esr-1~deb11u1
115.3.0esr-1~deb12u1
115.3.0esr-1
115.3.1esr-1~deb10u1
115.3.1esr-1~deb11u1
115.4.0esr-1~deb10u1
115.4.0esr-1~deb11u1
115.4.0esr-1~deb12u1
115.4.0esr-1
115.5.0esr-1~deb10u1
115.5.0esr-1~deb11u1
115.5.0esr-1~deb12u1
115.5.0esr-1
115.6.0esr-1~deb10u1
115.6.0esr-1~deb11u1
115.6.0esr-1~deb12u1
115.6.0esr-1
115.7.0esr-1~deb10u1
115.7.0esr-1~deb11u1
115.7.0esr-1~deb12u1
115.7.0esr-1
115.8.0esr-1~deb10u1
115.8.0esr-1~deb11u1
115.8.0esr-1~deb12u1
115.8.0esr-1
115.9.0esr-1~deb11u1
115.9.0esr-1~deb12u1
115.9.0esr-1
115.9.0esr-2
115.9.1esr-1~deb10u1
115.9.1esr-1~deb11u1
115.9.1esr-1~deb12u1
115.9.1esr-1
115.10.0esr-1~deb10u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
115.10.0esr-1~deb12u1

Affected versions

102.*

102.11.0esr-1
102.12.0esr-1~deb10u1
102.12.0esr-1~deb11u1
102.12.0esr-1~deb12u1
102.12.0esr-1
102.13.0esr-1~deb10u1
102.13.0esr-1~deb11u1
102.13.0esr-1~deb12u1
102.13.0esr-1
102.14.0esr-1~deb10u1
102.14.0esr-1~deb11u1
102.14.0esr-1~deb12u1
102.15.0esr-1~deb10u1
102.15.0esr-1~deb11u1
102.15.0esr-1~deb12u1
102.15.1esr-1~deb10u1
102.15.1esr-1~deb11u1
102.15.1esr-1~deb12u1

115.*

115.0.2esr-1
115.1.0esr-1
115.2.0esr-1
115.2.1esr-1
115.3.0esr-1~deb10u1
115.3.0esr-1~deb11u1
115.3.0esr-1~deb12u1
115.3.0esr-1
115.3.1esr-1~deb10u1
115.3.1esr-1~deb11u1
115.4.0esr-1~deb10u1
115.4.0esr-1~deb11u1
115.4.0esr-1~deb12u1
115.4.0esr-1
115.5.0esr-1~deb10u1
115.5.0esr-1~deb11u1
115.5.0esr-1~deb12u1
115.5.0esr-1
115.6.0esr-1~deb10u1
115.6.0esr-1~deb11u1
115.6.0esr-1~deb12u1
115.6.0esr-1
115.7.0esr-1~deb10u1
115.7.0esr-1~deb11u1
115.7.0esr-1~deb12u1
115.7.0esr-1
115.8.0esr-1~deb10u1
115.8.0esr-1~deb11u1
115.8.0esr-1~deb12u1
115.8.0esr-1
115.9.0esr-1~deb11u1
115.9.0esr-1~deb12u1
115.9.0esr-1
115.9.0esr-2
115.9.1esr-1~deb10u1
115.9.1esr-1~deb11u1
115.9.1esr-1~deb12u1
115.9.1esr-1
115.10.0esr-1~deb10u1
115.10.0esr-1~deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
115.10.0esr-1

Affected versions

102.*

102.11.0esr-1
102.12.0esr-1~deb10u1
102.12.0esr-1~deb11u1
102.12.0esr-1~deb12u1
102.12.0esr-1
102.13.0esr-1~deb10u1
102.13.0esr-1~deb11u1
102.13.0esr-1~deb12u1
102.13.0esr-1
102.14.0esr-1~deb10u1
102.14.0esr-1~deb11u1
102.14.0esr-1~deb12u1
102.15.0esr-1~deb10u1
102.15.0esr-1~deb11u1
102.15.0esr-1~deb12u1
102.15.1esr-1~deb10u1
102.15.1esr-1~deb11u1
102.15.1esr-1~deb12u1

115.*

115.0.2esr-1
115.1.0esr-1
115.2.0esr-1
115.2.1esr-1
115.3.0esr-1~deb10u1
115.3.0esr-1~deb11u1
115.3.0esr-1~deb12u1
115.3.0esr-1
115.3.1esr-1~deb10u1
115.3.1esr-1~deb11u1
115.4.0esr-1~deb10u1
115.4.0esr-1~deb11u1
115.4.0esr-1~deb12u1
115.4.0esr-1
115.5.0esr-1~deb10u1
115.5.0esr-1~deb11u1
115.5.0esr-1~deb12u1
115.5.0esr-1
115.6.0esr-1~deb10u1
115.6.0esr-1~deb11u1
115.6.0esr-1~deb12u1
115.6.0esr-1
115.7.0esr-1~deb10u1
115.7.0esr-1~deb11u1
115.7.0esr-1~deb12u1
115.7.0esr-1
115.8.0esr-1~deb10u1
115.8.0esr-1~deb11u1
115.8.0esr-1~deb12u1
115.8.0esr-1
115.9.0esr-1~deb11u1
115.9.0esr-1~deb12u1
115.9.0esr-1
115.9.0esr-2
115.9.1esr-1~deb10u1
115.9.1esr-1~deb11u1
115.9.1esr-1~deb12u1
115.9.1esr-1
115.10.0esr-1~deb10u1
115.10.0esr-1~deb11u1
115.10.0esr-1~deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:115.10.1-1~deb11u1

Affected versions

1:78.*

1:78.12.0-1
1:78.13.0-1~deb9u1
1:78.13.0-1~deb10u1
1:78.13.0-1~deb11u1
1:78.13.0-1
1:78.14.0-1~deb9u1
1:78.14.0-1~deb10u1
1:78.14.0-1~deb11u1
1:78.14.0-1

1:84.*

1:84.0~b3-1

1:85.*

1:85.0~b3-1

1:86.*

1:86.0~b3-1

1:88.*

1:88.0~b2-1

1:89.*

1:89.0~b2-1

1:90.*

1:90.0~b2-1

1:91.*

1:91.0~b1-1
1:91.0~b3-1
1:91.0~b5-1
1:91.0-1
1:91.0.2-1
1:91.1.0-1
1:91.1.1-1
1:91.2.0-1
1:91.2.1-1
1:91.3.0-1
1:91.3.2-1
1:91.4.0-1
1:91.4.1-1~deb9u1
1:91.4.1-1~deb10u1
1:91.4.1-1~deb11u1
1:91.4.1-1
1:91.5.0-1~deb9u1
1:91.5.0-1
1:91.5.0-2~deb10u1
1:91.5.0-2~deb11u1
1:91.5.0-2
1:91.5.1-1
1:91.6.0-1~deb9u1
1:91.6.0-1~deb10u1
1:91.6.0-1~deb11u1
1:91.6.0-1
1:91.6.1-1~deb9u1
1:91.6.1-1~deb10u1
1:91.6.1-1~deb11u1
1:91.6.1-1
1:91.6.2-1~deb9u1
1:91.6.2-1~deb10u1
1:91.6.2-1~deb11u1
1:91.6.2-1
1:91.7.0-1
1:91.7.0-2~deb9u1
1:91.7.0-2~deb10u1
1:91.7.0-2~deb11u1
1:91.7.0-2
1:91.8.0-1~deb9u1
1:91.8.0-1~deb10u1
1:91.8.0-1~deb11u1
1:91.8.0-1
1:91.8.1-1
1:91.9.0-1~deb9u1
1:91.9.0-1~deb10u1
1:91.9.0-1~deb11u1
1:91.9.0-1
1:91.10.0-1~deb9u1
1:91.10.0-1~deb10u1
1:91.10.0-1~deb11u1
1:91.10.0-1
1:91.11.0-1~deb10u1
1:91.11.0-1~deb11u1
1:91.11.0-1
1:91.12.0-1~deb10u1
1:91.12.0-1~deb11u1
1:91.13.0-1~deb10u1
1:91.13.0-1~deb11u1

1:102.*

1:102.0~b4-1
1:102.0~b7-1
1:102.0.1-1
1:102.0.2-1
1:102.1.0-1
1:102.1.1-1
1:102.1.2-1
1:102.2.0-1
1:102.2.1-1
1:102.2.2-1
1:102.3.0-1~deb10u1
1:102.3.0-1~deb11u1
1:102.3.0-1
1:102.3.1-1
1:102.3.2-1
1:102.3.3-1
1:102.4.0-1~deb10u1
1:102.4.0-1~deb11u1
1:102.4.0-1
1:102.4.1-1
1:102.5.0-1~deb10u1
1:102.5.0-1~deb11u1
1:102.5.0-1
1:102.5.1-1
1:102.6.0-1~deb10u1
1:102.6.0-1~deb11u1
1:102.6.0-1
1:102.7.1-1
1:102.7.1+1-1
1:102.7.2-1
1:102.8.0-1~deb10u1
1:102.8.0-1~deb11u1
1:102.8.0-1
1:102.9.0-1~deb10u1
1:102.9.0-1~deb11u1
1:102.9.0-1
1:102.9.1-1
1:102.10.0-1~deb10u1
1:102.10.0-1~deb11u1
1:102.10.0-1
1:102.11.0-1~deb10u1
1:102.11.0-1~deb11u1
1:102.11.0-1
1:102.12.0-1~deb10u1
1:102.12.0-1~deb11u1
1:102.12.0-1~deb12u1
1:102.12.0-1
1:102.13.0-1~deb10u1
1:102.13.0-1~deb11u1
1:102.13.0-1~deb12u1
1:102.13.0-1
1:102.13.1-1~deb10u1
1:102.13.1-1~deb11u1
1:102.13.1-1~deb12u1
1:102.13.1-1
1:102.14.0-1~deb10u1
1:102.14.0-1~deb11u1
1:102.14.0-1~deb12u1
1:102.15.0-1~deb10u1
1:102.15.0-1~deb11u1
1:102.15.0-1~deb12u1
1:102.15.1-1~deb10u1
1:102.15.1-1~deb11u1
1:102.15.1-1~deb12u1

1:103.*

1:103.0~b5-1

1:104.*

1:104.0~b2-1

1:110.*

1:110.0~b4-1

1:112.*

1:112.0~b1-1

1:113.*

1:113.0~b3-1

1:114.*

1:114.0~b2-1

1:115.*

1:115.0~b4-1
1:115.0~b6-1
1:115.0-1
1:115.0.1-1
1:115.0.1-2
1:115.1.0-1
1:115.1.1-1
1:115.2.0-1
1:115.2.2-1
1:115.3.0-1~deb12u1
1:115.3.0-1
1:115.3.1-1~deb10u1
1:115.3.1-1~deb11u1
1:115.3.1-1~deb12u1
1:115.3.1-1
1:115.4.1-1~deb10u1
1:115.4.1-1~deb11u1
1:115.4.1-1~deb12u1
1:115.4.1-1
1:115.5.0-1~deb10u1
1:115.5.0-1~deb11u1
1:115.5.0-1~deb12u1
1:115.5.0-1
1:115.5.1-1
1:115.5.2-1
1:115.6.0-1~deb10u1
1:115.6.0-1~deb11u1
1:115.6.0-1~deb12u1
1:115.6.0-1
1:115.7.0-1~deb10u1
1:115.7.0-1~deb11u1
1:115.7.0-1~deb12u1
1:115.7.0-1
1:115.8.0-1~deb10u1
1:115.8.0-1~deb11u1
1:115.8.0-1~deb12u1
1:115.8.0-1
1:115.8.1-1
1:115.9.0-1~deb10u1
1:115.9.0-1~deb11u1
1:115.9.0-1~deb12u1
1:115.9.0-1
1:115.10.1-1~deb10u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:115.10.1-1~deb12u1

Affected versions

1:102.*

1:102.11.0-1
1:102.12.0-1~deb10u1
1:102.12.0-1~deb11u1
1:102.12.0-1~deb12u1
1:102.12.0-1
1:102.13.0-1~deb10u1
1:102.13.0-1~deb11u1
1:102.13.0-1~deb12u1
1:102.13.0-1
1:102.13.1-1~deb10u1
1:102.13.1-1~deb11u1
1:102.13.1-1~deb12u1
1:102.13.1-1
1:102.14.0-1~deb10u1
1:102.14.0-1~deb11u1
1:102.14.0-1~deb12u1
1:102.15.0-1~deb10u1
1:102.15.0-1~deb11u1
1:102.15.0-1~deb12u1
1:102.15.1-1~deb10u1
1:102.15.1-1~deb11u1
1:102.15.1-1~deb12u1

1:103.*

1:103.0~b5-1

1:104.*

1:104.0~b2-1

1:110.*

1:110.0~b4-1

1:112.*

1:112.0~b1-1

1:113.*

1:113.0~b3-1

1:114.*

1:114.0~b2-1

1:115.*

1:115.0~b4-1
1:115.0~b6-1
1:115.0-1
1:115.0.1-1
1:115.0.1-2
1:115.1.0-1
1:115.1.1-1
1:115.2.0-1
1:115.2.2-1
1:115.3.0-1~deb12u1
1:115.3.0-1
1:115.3.1-1~deb10u1
1:115.3.1-1~deb11u1
1:115.3.1-1~deb12u1
1:115.3.1-1
1:115.4.1-1~deb10u1
1:115.4.1-1~deb11u1
1:115.4.1-1~deb12u1
1:115.4.1-1
1:115.5.0-1~deb10u1
1:115.5.0-1~deb11u1
1:115.5.0-1~deb12u1
1:115.5.0-1
1:115.5.1-1
1:115.5.2-1
1:115.6.0-1~deb10u1
1:115.6.0-1~deb11u1
1:115.6.0-1~deb12u1
1:115.6.0-1
1:115.7.0-1~deb10u1
1:115.7.0-1~deb11u1
1:115.7.0-1~deb12u1
1:115.7.0-1
1:115.8.0-1~deb10u1
1:115.8.0-1~deb11u1
1:115.8.0-1~deb12u1
1:115.8.0-1
1:115.8.1-1
1:115.9.0-1~deb10u1
1:115.9.0-1~deb11u1
1:115.9.0-1~deb12u1
1:115.9.0-1
1:115.10.1-1~deb10u1
1:115.10.1-1~deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:115.10.1-1

Affected versions

1:102.*

1:102.11.0-1
1:102.12.0-1~deb10u1
1:102.12.0-1~deb11u1
1:102.12.0-1~deb12u1
1:102.12.0-1
1:102.13.0-1~deb10u1
1:102.13.0-1~deb11u1
1:102.13.0-1~deb12u1
1:102.13.0-1
1:102.13.1-1~deb10u1
1:102.13.1-1~deb11u1
1:102.13.1-1~deb12u1
1:102.13.1-1
1:102.14.0-1~deb10u1
1:102.14.0-1~deb11u1
1:102.14.0-1~deb12u1
1:102.15.0-1~deb10u1
1:102.15.0-1~deb11u1
1:102.15.0-1~deb12u1
1:102.15.1-1~deb10u1
1:102.15.1-1~deb11u1
1:102.15.1-1~deb12u1

1:103.*

1:103.0~b5-1

1:104.*

1:104.0~b2-1

1:110.*

1:110.0~b4-1

1:112.*

1:112.0~b1-1

1:113.*

1:113.0~b3-1

1:114.*

1:114.0~b2-1

1:115.*

1:115.0~b4-1
1:115.0~b6-1
1:115.0-1
1:115.0.1-1
1:115.0.1-2
1:115.1.0-1
1:115.1.1-1
1:115.2.0-1
1:115.2.2-1
1:115.3.0-1~deb12u1
1:115.3.0-1
1:115.3.1-1~deb10u1
1:115.3.1-1~deb11u1
1:115.3.1-1~deb12u1
1:115.3.1-1
1:115.4.1-1~deb10u1
1:115.4.1-1~deb11u1
1:115.4.1-1~deb12u1
1:115.4.1-1
1:115.5.0-1~deb10u1
1:115.5.0-1~deb11u1
1:115.5.0-1~deb12u1
1:115.5.0-1
1:115.5.1-1
1:115.5.2-1
1:115.6.0-1~deb10u1
1:115.6.0-1~deb11u1
1:115.6.0-1~deb12u1
1:115.6.0-1
1:115.7.0-1~deb10u1
1:115.7.0-1~deb11u1
1:115.7.0-1~deb12u1
1:115.7.0-1
1:115.8.0-1~deb10u1
1:115.8.0-1~deb11u1
1:115.8.0-1~deb12u1
1:115.8.0-1
1:115.8.1-1
1:115.9.0-1~deb10u1
1:115.9.0-1~deb11u1
1:115.9.0-1~deb12u1
1:115.9.0-1
1:115.10.1-1~deb10u1
1:115.10.1-1~deb11u1
1:115.10.1-1~deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}