CVE-2024-3855: Medium severity firefox vulnerability
Published Apr 16, 2024
·Updated
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<125
125
Mozilla Firefox<125.0
debian/firefox
138.0.1-1
Event History
Apr 16, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
DescriptionWeakness
May 2, 2024
Data Sourced
via Launchpad·07:33 AM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·07:53 AM
RemedyDescriptionSeverityAffected Software
May 2, 2025
Data Sourced
via Debian·02:18 PM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-3855?
CVE-2024-3855 is classified as a significant vulnerability due to its potential for causing out-of-bounds reads.
2
How do I fix CVE-2024-3855?
To fix CVE-2024-3855, update to Mozilla Firefox version 125 or later.
3
Which versions of Firefox are affected by CVE-2024-3855?
CVE-2024-3855 affects all versions of Firefox prior to version 125.
4
What kind of vulnerability is CVE-2024-3855?
CVE-2024-3855 is a JIT optimization vulnerability that can lead to out-of-bounds memory access.
5
Is there a fix available for CVE-2024-3855 on Debian systems?
Yes, Debian systems can resolve CVE-2024-3855 by upgrading to the Firefox package version 134.0.2-3 or later.