PT-2021-7957 · Mozilla+1 · Firefox+1

Atila Butkovits

·

Published

2021-12-07

·

Updated

2023-07-11

·

CVE-2021-4128

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 95
Description The issue is related to a graphics object not being correctly protected when transitioning in and out of fullscreen mode, resulting in memory corruption and a potentially exploitable crash. This problem affects Firefox on MacOS, with other operating systems being unaffected. The vulnerability is also described as a use-after-free issue, which could allow a remote attacker to cause a denial of service.
Recommendations For versions prior to 95, update to version 95 or later to resolve the issue. As a temporary workaround, consider avoiding the use of fullscreen mode in Firefox on MacOS until the update is applied.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2023-07573
CVE-2021-4128

Affected Products

Alt Linux
Firefox