PT-2021-7312 · Mozilla+1 · Firefox For Android+2

Wladimir Palant

·

Published

2021-06-03

·

Updated

2024-12-12

·

CVE-2021-29963

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 89 Firefox for Android versions prior to 89
Description The issue is related to insufficient authentication of data in the "Private Browsing" mode of Mozilla Firefox. It allows a remote attacker to cause a denial of service. The problem specifically affects the address bar search suggestions in private browsing mode, which were reusing session data from normal mode. This issue only affects Firefox for Android, with other operating systems being unaffected.
Recommendations For Firefox versions prior to 89, update to version 89 or later to resolve the issue. For Firefox for Android versions prior to 89, update to version 89 or later to resolve the issue. As a temporary workaround, consider disabling the address bar search suggestions in private browsing mode until a patch is available.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1919
ALT-PU-2021-3368
ALT-PU-2022-1782
BDU:2022-05612
CVE-2021-29963
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox
Firefox For Android