Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-43097

Опубликовано: 03 янв. 2025
Источник: debian
EPSS Низкий

Описание

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefox-esrfixed128.8.0esr-1package
thunderbirdfixed1:128.8.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-16/#CVE-2024-43097

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-18/#CVE-2024-43097

EPSS

Процентиль: 17%
0.00258
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
nvd
больше 1 года назад

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
github
больше 1 года назад

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость компонента SkRegion.cpp веб-браузера Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

suse-cvrf
больше 1 года назад

Security update for MozillaFirefox

EPSS

Процентиль: 17%
0.00258
Низкий