Web application manifests were stored by using an insecure MD5 hash which
allowed for a hash collision to overwrite another application’s manifest.
This could have been exploited to run arbitrary code in another
application’s context. This issue only affects Firefox for Android. Other
versions of Firefox are unaffected. This vulnerability affects Firefox <
126.
Author | Note |
---|---|
tyhicks | mozjs contains a copy of the SpiderMonkey JavaScript engine |
mdeslaur | starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap starting with Ubuntu 24.04, the thunderbird package is just a script that installs the Thunderbird snap This only affects android |
bugzilla.mozilla.org/show_bug.cgi?id=1871109
launchpad.net/bugs/cve/CVE-2024-4765
nvd.nist.gov/vuln/detail/CVE-2024-4765
security-tracker.debian.org/tracker/CVE-2024-4765
www.cve.org/CVERecord?id=CVE-2024-4765
www.mozilla.org/en-US/security/advisories/mfsa2024-21/#CVE-2024-4765
www.mozilla.org/security/advisories/mfsa2024-21/