CVE-2024-1546

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

27 Mar 2025, 14:35

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
First Time Mozilla thunderbird
Mozilla firefox
Mozilla
Debian debian Linux
Debian
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1843752 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1843752 - Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html - () https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html - Mailing List
References () https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html - () https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html - Mailing List
References () https://www.mozilla.org/security/advisories/mfsa2024-05/ - () https://www.mozilla.org/security/advisories/mfsa2024-05/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-06/ - () https://www.mozilla.org/security/advisories/mfsa2024-06/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-07/ - () https://www.mozilla.org/security/advisories/mfsa2024-07/ - Vendor Advisory

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1843752 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1843752 -
References () https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html - () https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html -
References () https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html - () https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html -
References () https://www.mozilla.org/security/advisories/mfsa2024-05/ - () https://www.mozilla.org/security/advisories/mfsa2024-05/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-06/ - () https://www.mozilla.org/security/advisories/mfsa2024-06/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-07/ - () https://www.mozilla.org/security/advisories/mfsa2024-07/ -

05 Nov 2024, 16:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

04 Mar 2024, 09:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/03/msg00000.html -
  • () https://lists.debian.org/debian-lts-announce/2024/03/msg00001.html -
Summary
  • (es) Al almacenar y volver a acceder a datos en un canal de red, es posible que se haya confundido la longitud de los bufferse, lo que resulta en una lectura de memoria fuera de los límites. Esta vulnerabilidad afecta a Firefox &lt; 123, Firefox ESR &lt; 115.8 y Thunderbird &lt; 115.8.

20 Feb 2024, 20:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2024-07/ -
Summary (en) When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8. (en) When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

20 Feb 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 14:15

Updated : 2025-03-27 14:35


NVD link : CVE-2024-1546

Mitre link : CVE-2024-1546

CVE.ORG link : CVE-2024-1546


JSON object : View

Products Affected

debian

  • debian_linux

mozilla

  • firefox
  • thunderbird
CWE
CWE-125

Out-of-bounds Read