CVE-2024-2612: Use After Free
If an attacker could find a way to trigger a particular code path in SafeRefPtr, it could have triggered a crash or potentially be leveraged to achieve code execution.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-13/#CVE-2024-2612
Other sources
If an attacker could find a way to trigger a particular code path in SafeRefPtr, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
— Launchpad
If an attacker could find a way to trigger a particular code path in SafeRefPtr, it could have triggered a crash or potentially be leveraged to achieve code execution.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2612?
CVE-2024-2612 has a high severity rating due to potential crash or code execution exploits.
How do I fix CVE-2024-2612?
To fix CVE-2024-2612, users should update to Firefox 125 or later, Firefox ESR 116.0 or later, or Thunderbird 116.0 or later.
Which versions are affected by CVE-2024-2612?
CVE-2024-2612 affects Firefox versions up to 124, Firefox ESR versions up to 115.9, and Thunderbird versions up to 115.9.
Can CVE-2024-2612 lead to security breaches?
Yes, CVE-2024-2612 could be exploited to achieve code execution, leading to potential security breaches.
Is CVE-2024-2612 specific to certain operating systems?
CVE-2024-2612 is a vulnerability in Mozilla products and can affect any operating system that supports Firefox, Firefox ESR, and Thunderbird.