CVE-2024-3302: Low severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
Per initial information provided via VINCE:
Mozilla has reserved CVE-2024-3302 for this issue in the Gecko networking implementation; the Firefox and Thunderbird clients would be vulnerable to a DoS from a malicious server.
— Red Hat
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3302?
CVE-2024-3302 has been classified as a denial of service (DoS) vulnerability affecting certain versions of Mozilla Firefox and Thunderbird.
How do I fix CVE-2024-3302?
To mitigate CVE-2024-3302, users should update their installations of Mozilla Firefox and Thunderbird to versions beyond 115.10 or follow the specific remediation instructions for their OS package.
Which versions of Mozilla Firefox are affected by CVE-2024-3302?
CVE-2024-3302 affects Mozilla Firefox versions up to and including 115.10.
Which versions of Mozilla Thunderbird are affected by CVE-2024-3302?
CVE-2024-3302 impacts Mozilla Thunderbird versions up to and including 115.10.
What are the implications of CVE-2024-3302 on users' applications?
CVE-2024-3302 could allow attackers to disrupt service, leading to potential downtime for users relying on Firefox or Thunderbird.