First published: Tue Mar 23 2021(Updated: )
Mozilla developers and community members Alexis Beingessner, Tyson Smith, Julien Wajsberg, and Matthew Gregan reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <78.9 | 78.9 |
Firefox | <87.0 | |
Firefox ESR | <78.9 | |
Thunderbird | <78.9 | |
Firefox | <87 | 87 |
Firefox ESR | <78.9 | 78.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-23987 is a memory safety bug present in Firefox 86 and Firefox ESR 78.8.
Mozilla developers and community members Matthew Gregan, Tyson Smith, Julien Wajsberg, and Alexis Beingessner reported CVE-2021-23987.
CVE-2021-23987 has a severity rating of high.
Mozilla Thunderbird 78.9, Firefox ESR 78.9, and Firefox 87 are affected by CVE-2021-23987.
To fix CVE-2021-23987, update to Mozilla Thunderbird 78.9, Firefox ESR 78.9, or Firefox 87.