Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2024-4765
HistoryMay 14, 2024 - 6:15 p.m.

CVE-2024-4765

2024-05-1418:15:13
Debian Security Bug Tracker
security-tracker.debian.org
6
web application
md5 hash
hash collision
arbitrary code execution
firefox for android

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

9.0%

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application’s manifest. This could have been exploited to run arbitrary code in another application’s context. This issue only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 126.

OSVersionArchitecturePackageVersionFilename
Debian999allfirefox< 130.0.1-1firefox_130.0.1-1_all.deb

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

9.0%