Input validation error in Firefox for Android and Mozilla Firefox - CVE-2024-5699

 

Input validation error in Firefox for Android and Mozilla Firefox - CVE-2024-5699

Published: June 11, 2024


Vulnerability identifier: #VU91750
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-5699
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the way Firefox handles cookie prefixes. Cookie prefixes such as __Secure were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix.


Affected software

Firefox for Android
Mozilla Firefox
Gentoo Linux
Ubuntu
openEuler
Fedora
www-client/firefox
firefox
firefox (Ubuntu package)
firefox-debuginfo
firefox-debugsource

How to mitigate CVE-2024-5699

Install updates from vendor's website.

Firefox for Android - update to 127.0
Mozilla Firefox - update to 127.0
www-client/firefox - update to 104
firefox - update to 127.0-1.fc40
firefox (Ubuntu package) - update to 127.0.2+build1-0ubuntu0.20.04.1
firefox - update to 128.8.0-1
firefox-debuginfo - update to 128.8.0-1
firefox-debugsource - update to 128.8.0-1

External References

Related Security Bulletins