Skip to content

Commit

Permalink
Add Advisories for Firefox 126
Browse files Browse the repository at this point in the history
  • Loading branch information
tomrittervg committed May 10, 2024
1 parent 605fcd6 commit d107216
Show file tree
Hide file tree
Showing 2 changed files with 194 additions and 0 deletions.
138 changes: 138 additions & 0 deletions announce/2024/mfsa2024-21.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
## mfsa2024-21.yml
announced: May 14, 2024
impact: high
fixed_in:
- Firefox 126
title: Security Vulnerabilities fixed in Firefox 126
advisories:
MFSA-RESERVE-2024-1879093:
title: Use-after-free when audio input connected with multiple consumers
impact: high
reporter: Jan-Ivar Bruaroey
description: |
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free.
bugs:
- url: 1879093
CVE-2024-4367:
title: Arbitrary JavaScript execution in PDF.js
impact: high
reporter: Thomas Rinsma of Codean Labs
description: |
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
bugs:
- url: 1893645
MFSA-RESERVE-2024-1871109:
title: Web application manifests could have been overwritten via hash collision
impact: moderate
reporter: Dana Keeler
description: |
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another applications manifest. This could have been exploited to run arbitrary code in another applications context. <br>*This issue only affects Firefox for Android. Other versions of Firefox are unaffected.*
bugs:
- url: 1871109
MFSA-RESERVE-2024-1871214:
title: Fullscreen notification could have been obscured on Firefox for Android
impact: moderate
reporter: Hafiizh
description: |
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have lead to potential user confusion and spoofing attacks.<br>*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*
bugs:
- url: 1871214
- url: 1871217
MFSA-RESERVE-2024-1878577:
title: IndexDB files retained in private browsing mode
impact: moderate
reporter: Kim Do Hun via Tor Browser
description: |
If the <code>browser.privatebrowsing.autostart</code> preference is enabled, IndexDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox.
bugs:
- url: 1878577
MFSA-RESERVE-2024-1886082:
title: Potential permissions request bypass via clickjacking
impact: moderate
reporter: Hafiizh
description: |
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions.
bugs:
- url: 1886082
MFSA-RESERVE-2024-1886108:
title: Cross-Origin responses could be distinguished between script and non-script content-types
impact: moderate
reporter: Shaheen Fazim
description: |
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin.
bugs:
- url: 1886108
MFSA-RESERVE-2024-1893270:
title: Use-after-free could occur when printing to PDF
impact: moderate
reporter: Irvan Kurniawan
description: |
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash.
bugs:
- url: 1893270
MFSA-RESERVE-2024-1893891:
title: Failed allocation could lead to use-after-free
impact: moderate
reporter: Irvan Kurniawan
description: |
A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution.
bugs:
- url: 1893891
MFSA-RESERVE-2024-1870579:
title: Use of insecure rand() function to generate nonce
impact: low
reporter: Hanno Böck
description: |
An HTTP digest authentication nonce value was generated using <code>rand()</code> which could lead to predictable values.
bugs:
- url: 1870579
MFSA-RESERVE-2024-1875248:
title: URL bar could be cleared after network error
impact: low
reporter: Islam
description: |
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site.
bugs:
- url: 1875248
MFSA-RESERVE-2024-1886598:
title: Undefined behavior in ShmemCharMapHashEntry()
impact: low
reporter: Ronald Crane
description: |
The <code>ShmemCharMapHashEntry()</code> code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members.
bugs:
- url: 1886598
MFSA-RESERVE-2024-1887332:
title: Invalid memory access in the built-in profiler
impact: low
reporter: Lukas Bernhard
description: |
An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. <i>Note:</i> This issue only affects the application when the profiler is running.
bugs:
- url: 1887332
MFSA-RESERVE-2024-1887343:
title: Window may remain disabled after file dialog is shown in full-screen
impact: low
reporter: Raphael
description: |
A file dialog shown while in full-screen mode could have resulted in the window remaining disabled.
bugs:
- url: 1887343
MFSA-RESERVE-2024-2:
title: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11
impact: moderate
reporter: Daniel Holbert and the Mozilla Fuzzing Team
description: |
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
bugs:
- url: 1878199, 1893340
desc: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11
MFSA-RESERVE-2024-4:
title: Memory safety bugs fixed in Firefox 126
impact: moderate
reporter: Mozilla Fuzzing Team
description: |
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
bugs:
- url: 1838834, 1889291, 1889595, 1890204, 1891545
desc: Memory safety bugs fixed in Firefox 126
56 changes: 56 additions & 0 deletions announce/2024/mfsa2024-22.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
## mfsa2024-22.yml
announced: May 14, 2024
impact: high
fixed_in:
- Firefox ESR 115.11
title: Security Vulnerabilities fixed in Firefox ESR 115.11
advisories:
CVE-2024-4367:
title: Arbitrary JavaScript execution in PDF.js
impact: high
reporter: Thomas Rinsma of Codean Labs
description: |
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
bugs:
- url: 1893645
MFSA-RESERVE-2024-1878577:
title: IndexDB files retained in private browsing mode
impact: moderate
reporter: Kim Do Hun via Tor Browser
description: |
If the <code>browser.privatebrowsing.autostart</code> preference is enabled, IndexDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox.
bugs:
- url: 1878577
MFSA-RESERVE-2024-1886082:
title: Potential permissions request bypass via clickjacking
impact: moderate
reporter: Hafiizh
description: |
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions.
bugs:
- url: 1886082
MFSA-RESERVE-2024-1886108:
title: Cross-Origin responses could be distinguished between script and non-script content-types
impact: moderate
reporter: Shaheen Fazim
description: |
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin.
bugs:
- url: 1886108
MFSA-RESERVE-2024-1893270:
title: Use-after-free could occur when printing to PDF
impact: moderate
reporter: Irvan Kurniawan
description: |
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash.
bugs:
- url: 1893270
MFSA-RESERVE-2024-2:
title: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11
impact: moderate
reporter: Daniel Holbert and the Mozilla Fuzzing Team
description: |
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
bugs:
- url: 1878199, 1893340
desc: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11

0 comments on commit d107216

Please sign in to comment.