In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1895081 | issue tracking |
https://www.mozilla.org/security/advisories/mfsa2024-29/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-30/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-31/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-32/ | vendor advisory |