CVE-2024-6600

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

04 Apr 2025, 14:43

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1888340 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1888340 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2024-29/ - () https://www.mozilla.org/security/advisories/mfsa2024-29/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-30/ - () https://www.mozilla.org/security/advisories/mfsa2024-30/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-31/ - () https://www.mozilla.org/security/advisories/mfsa2024-31/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-32/ - () https://www.mozilla.org/security/advisories/mfsa2024-32/ - Vendor Advisory
First Time Mozilla firefox
Mozilla thunderbird
Mozilla
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

21 Nov 2024, 09:49

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1888340 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1888340 -
References () https://www.mozilla.org/security/advisories/mfsa2024-29/ - () https://www.mozilla.org/security/advisories/mfsa2024-29/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-30/ - () https://www.mozilla.org/security/advisories/mfsa2024-30/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-31/ - () https://www.mozilla.org/security/advisories/mfsa2024-31/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-32/ - () https://www.mozilla.org/security/advisories/mfsa2024-32/ -

29 Oct 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3
CWE CWE-770

16 Jul 2024, 18:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2024-31/ -
  • () https://www.mozilla.org/security/advisories/mfsa2024-32/ -
Summary
  • (es) Debido a que las grandes comprobaciones de asignación en Angle para los sombreadores GLSL son demasiado indulgentes, podría ocurrir un acceso fuera de los límites al asignar más de 8192 entradas en la memoria privada del sombreador en Mac OS. Esta vulnerabilidad afecta a Firefox &lt; 128 y Firefox ESR &lt; 115.13.
Summary (en) Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13. (en) Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

09 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 15:15

Updated : 2025-04-04 14:43


NVD link : CVE-2024-6600

Mitre link : CVE-2024-6600

CVE.ORG link : CVE-2024-6600


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
CWE-770

Allocation of Resources Without Limits or Throttling