CVE-2024-5695: Critical severity Mozilla Firefox vulnerability
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.3-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 127
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5695?
CVE-2024-5695 has a high severity due to potential memory corruption risks.
How do I fix CVE-2024-5695?
To mitigate CVE-2024-5695, update to Firefox version 131.0.3-1 or later.
Which versions of Firefox are affected by CVE-2024-5695?
CVE-2024-5695 affects versions of Firefox prior to 127.
What are the consequences of CVE-2024-5695 if exploited?
Exploitation of CVE-2024-5695 can lead to unexpected application behavior and possible data corruption.
Is there any workaround for CVE-2024-5695 until I can update?
Currently, there are no effective workarounds for CVE-2024-5695; updating Firefox is recommended.