VDB
BDU%3A2024-04733
BDU%3A2024-04733
PUBLISHED
CVSS 7.599999904632568 HIGH
Уязвимость библиотеки PDF.js связанная с доступом к ресурсу через несовместимые типы, позволяющая нарушителю выполнить произвольный JavaScript-код
Risk Scores
CVSS 2.0
7.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., ООО «РусБИТех-Астра», Novell Inc., Сообщество свободного программного обеспечения, Canonical Ltd., ООО «Ред Софт», АО «ИВК», Mozilla Corp., АО "НППКТ", Open-Xchange, ООО «Новые Облачные Технологии» | Red Hat Enterprise Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), OpenSUSE Leap, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, Debian GNU/Linux, openSUSE Tumbleweed, Ubuntu, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise High Performance Computing, SUSE Enterprise Storage, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Desktop Applications, SUSE Linux Enterprise Module for Package Hub, АЛЬТ СП 10, SUSE Linux Enterprise Workstation Extension, SUSE Liberty Linux, Thunderbird, Firefox, Firefox ESR, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), PDF.js, OX App Suite frontend, Mailion (запись в едином реестре российских программ №12707) |
Timeline
- May 22, 2024 PoC Published
- Jun 21, 2024 CVE Published
- Sep 26, 2025 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-21/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/ url
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ url
- https://bugzilla.mozilla.org/show_bug.cgi?id=1893645 url
- http://ubuntu.com/security/notices/USN-6782-1 url
- http://ubuntu.com/security/notices/USN-6779-2 url
- http://ubuntu.com/security/notices/USN-6779-1 url
- https://security-tracker.debian.org/tracker/CVE-2024-4367 url
- https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html url
- https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html url
- https://www.suse.com/security/cve/CVE-2024-4367.html url
- https://access.redhat.com/security/cve/CVE-2024-4367 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.11/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2024-0830SE17 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20241017SE16 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-1031SE47 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://github.com/advisories/GHSA-wgrm-67xf-hhpq advisory
- https://mozilla.github.io/pdf.js/getting_started/#download advisory