PT-2021-22163 · Mozilla+3 · Firefox+5

James Lee

·

Published

2021-09-07

·

Updated

2024-12-12

·

CVE-2021-38492

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 92 Thunderbird versions prior to 91.1 Thunderbird versions prior to 78.14 Firefox ESR versions prior to 78.14 Firefox ESR versions prior to 91.1
Description When delegating navigations to the operating system, Firefox would accept the mk scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. This bug only affects Firefox for Windows, with other operating systems being unaffected.
Recommendations For Firefox versions prior to 92, update to version 92 or later. For Thunderbird versions prior to 91.1, update to version 91.1 or later. For Thunderbird versions prior to 78.14, update to version 78.14 or later. For Firefox ESR versions prior to 78.14, update to version 78.14 or later. For Firefox ESR versions prior to 91.1, update to version 91.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2021-2739
ALT-PU-2021-2759
ALT-PU-2021-2762
ALT-PU-2021-2766
ALT-PU-2021-2794
ALT-PU-2021-2807
ALT-PU-2021-2830
ALT-PU-2021-2849
ALT-PU-2021-2881
ALT-PU-2021-2942
ALT-PU-2021-3368
ALT-PU-2022-1782
ALT-PU-2023-4336
CVE-2021-38492
OPENSUSE-SU-2021:1367-1
OPENSUSE-SU-2021:1635-1
OPENSUSE-SU-2021:3331-1
OPENSUSE-SU-2021:3451-1
OPENSUSE-SU-2021:4150-1
OPENSUSE-SU-2021_1367-1
OPENSUSE-SU-2021_1635-1
OPENSUSE-SU-2021_3331-1
OPENSUSE-SU-2021_3451-1
OPENSUSE-SU-2021_4150-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2021:14821-1
SUSE-SU-2021:14826-1
SUSE-SU-2021:3191-1
SUSE-SU-2021:3331-1
SUSE-SU-2021:3451-1
SUSE-SU-2021:4150-1
SUSE-SU-2021_14821-1
SUSE-SU-2021_14826-1
SUSE-SU-2022:1577-1
SUSE-SU-2022:1582-1
SUSE-SU-2022_1577-1
SUSE-SU-2022_1582-1

Affected Products

Alt Linux
Firefox
Firefox Esr
Internet Explorer
Suse
Thunderbird