CVE-2024-4765

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1871109 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1871109 -
References () https://www.mozilla.org/security/advisories/mfsa2024-21/ - () https://www.mozilla.org/security/advisories/mfsa2024-21/ -

29 Aug 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) Los manifiestos de las aplicaciones web se almacenaban mediante un hash MD5 inseguro que permitía que una colisión de hash sobrescribiera el manifiesto de otra aplicación. Esto podría haberse aprovechado para ejecutar código arbitrario en el contexto de otra aplicación. *Este problema sólo afecta a Firefox para Android. Otras versiones de Firefox no se ven afectadas.* Esta vulnerabilidad afecta a Firefox &lt; 126.
CWE CWE-327

14 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 18:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4765

Mitre link : CVE-2024-4765

CVE.ORG link : CVE-2024-4765


JSON object : View

Products Affected

No product.

CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm