CVE-2024-5688: Use After Free
Published Jun 11, 2024
·Updated
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant.
Affected Software
11 affected componentsFixes available
redhat/firefox<115.12
115.12
redhat/thunderbird<115.12
115.12
debian/firefox
131.0.3-1
debian/firefox-esr
115.14.0esr-1~deb11u1128.3.1esr-1~deb11u1115.14.0esr-1~deb12u1128.3.1esr-1~deb12u1128.3.1esr-2
debian/thunderbird
1:115.12.0-1~deb11u11:115.16.0esr-1~deb11u11:115.12.0-1~deb12u11:115.16.0esr-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<115.12
115.12
Mozilla Firefox<127
127
Mozilla Firefox ESR<115.12
115.12
Mozilla Firefox<115.12
Mozilla Firefox<127.0
Mozilla Thunderbird<115.12
Event History
Jun 11, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·08:45 PM
DescriptionSeverityAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·12:12 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·12:23 PM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-5688?
CVE-2024-5688 is considered a critical vulnerability due to the potential for a use-after-free condition.
2
How do I fix CVE-2024-5688?
To fix CVE-2024-5688, users should update to Mozilla Firefox or Thunderbird versions 115.12 or later.
3
What products are affected by CVE-2024-5688?
CVE-2024-5688 affects Mozilla Firefox ESR, Mozilla Thunderbird, and versions of Firefox and Thunderbird up to 115.12.
4
What type of vulnerability is CVE-2024-5688?
CVE-2024-5688 is a use-after-free vulnerability that may arise during garbage collection processes.
5
What are the potential impacts of CVE-2024-5688?
The potential impacts of CVE-2024-5688 include crashes and possible arbitrary code execution.