CVE-2024-2607: High severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. Note: This issue only affected Armv7-A systems. Other operating systems are unaffected.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-13/#CVE-2024-2607
— Red Hat
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. Note: This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
— Launchpad
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. Note: This issue only affected Armv7-A systems. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2607?
CVE-2024-2607 is considered a critical vulnerability due to the potential for arbitrary code execution on affected systems.
How do I fix CVE-2024-2607?
To fix CVE-2024-2607, update Mozilla Firefox to version 125 or higher, and Firefox ESR or Thunderbird to version 116 or higher as applicable.
Which systems are affected by CVE-2024-2607?
CVE-2024-2607 affects Armv7-A systems running specific versions of Mozilla Firefox, Firefox ESR, and Thunderbird.
What types of attacks can CVE-2024-2607 facilitate?
CVE-2024-2607 can facilitate remote code execution attacks, allowing an attacker to execute arbitrary code on the vulnerable system.
When was CVE-2024-2607 first reported?
CVE-2024-2607 was first reported on July 24, 2024.