First published: Tue Jan 26 2021(Updated: )
Mozilla developers Alexis Beingessner, Christian Holler, Andrew McCreight, Tyson Smith, Jon Coppeard, André Bargull, Jason Kratzer, Jesse Schwartzentruber, Steve Fink, Byron Campen reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 | |
Thunderbird | <78.7 | 78.7 |
Firefox | <85.0 | |
Firefox ESR | <78.7 | |
Thunderbird | <78.7 | |
Firefox | <85 | 85 |
Firefox ESR | <78.7 | 78.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-23964 is a memory safety vulnerability that can potentially be exploited, requiring immediate attention.
To fix CVE-2021-23964, update your Mozilla Firefox to version 85 or Mozilla Thunderbird to version 78.7.
CVE-2021-23964 affects Firefox versions prior to 85 and Thunderbird versions prior to 78.7.
There are no known workarounds for CVE-2021-23964; updating to the latest versions is the recommended action.
CVE-2021-23964 has the potential to lead to data corruption or loss if exploited.