Want relief keeping up with product patching, upgrades, and more?  Learn how our Managed Services for law firms can help you.

Mozilla Firefox (Desktop) Critical Security Vulnerabilities

March 2024

Cornerstone.IT Gold Microsoft Partner

Mozilla Firefox (Desktop): Please see the list of vulnerability and fixes identified below.

Identified Vulnerabilities

Privileged JavaScript Execution via Event Handlers (CVE-2024-29944)

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox.

Out-of-bounds access via Range Analysis bypass (CVE-2024-29943)

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

Patch and Upgrade Available


Mozilla Foundation issued official patch/upgrade in their Security Advisory Board.

Sources

Cornerstone.IT