PT-2021-4031 · Mozilla+8 · Firefox Esr+10

Gabriele Svelto

+1

·

Published

2021-08-26

·

Updated

2024-12-12

·

CVE-2021-38493

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions 91 and earlier Firefox ESR versions 78.13 and earlier Thunderbird versions 78.13 and earlier
Description The issue is related to memory safety bugs, which can lead to memory corruption. With sufficient effort, these bugs could potentially be exploited to run arbitrary code. The vulnerability is also described as a buffer overflow in memory, which could allow a remote attacker to execute arbitrary code.
Recommendations For Firefox versions 91 and earlier, update to version 92 or later. For Firefox ESR versions 78.13 and earlier, update to version 78.14 or later. For Thunderbird versions 78.13 and earlier, update to version 78.14 or later.

Exploit

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2636
ALT-PU-2021-2718
ALT-PU-2021-2739
ALT-PU-2021-2759
ALT-PU-2021-2794
ALT-PU-2021-2830
ALT-PU-2021-2849
ALT-PU-2021-2942
ALT-PU-2021-3368
ALT-PU-2022-1782
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2023-1138
ALT-PU-2023-4336
BDU:2021-04558
CESA-2021_3494
CESA-2021_3497
CESA-2021_3498
CESA-2021_3499
CVE-2021-38493
DLA-2756-1
DLA-2757-1
DSA-4969-1
DSA-4973-1
MGASA-2021-0425
MGASA-2021-0427
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2021:1635-1
OPENSUSE-SU-2021:4150-1
OPENSUSE-SU-2021_1635-1
OPENSUSE-SU-2021_4150-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2021:3494
RHSA-2021:3495
RHSA-2021:3496
RHSA-2021:3497
RHSA-2021:3498
RHSA-2021:3499
RHSA-2021:3500
RHSA-2021:3501
RHSA-2021_3494
RHSA-2021_3497
RHSA-2021_3498
RHSA-2021_3499
RLSA-2021:3497
RLSA-2021:3499
SUSE-SU-2021:4150-1
USN-5074-1
USN-5146-1

Affected Products

Alt Linux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu