PT-2021-8092 · Mozilla+2 · Firefox Esr+3
Cristiano Giuffrida
+3
·
Published
2021-02-16
·
Updated
2023-09-22
·
CVE-2021-29955
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox ESR versions prior to 78.9
Firefox versions prior to 87
Description
The issue is related to insufficient neutralization of special elements in a request, which may allow a remote attacker to access confidential data. It is also described as a transient execution vulnerability, specifically Floating Point Value Injection (FPVI), allowing an attacker to leak arbitrary memory addresses and potentially enabling JIT type confusion attacks.
Recommendations
For Firefox ESR versions prior to 78.9, update to version 78.9 or later.
For Firefox versions prior to 87, update to version 87 or later.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Firefox Esr