CVE-2021-23994: High severity thunderbird vulnerability
Published Apr 19, 2021
·Updated
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write.
Affected Software
9 affected componentsFixes available
debian/firefox
118.0.2-1
debian/firefox-esr
91.12.0esr-1~deb10u1115.3.1esr-1~deb10u1102.15.0esr-1~deb11u1115.3.1esr-1~deb11u1102.15.1esr-1~deb12u1115.3.0esr-1~deb12u1115.3.0esr-1
debian/thunderbird
1:91.12.0-1~deb10u11:115.3.1-1~deb10u11:102.13.1-1~deb11u11:115.3.1-1~deb11u11:102.15.1-1~deb12u11:115.3.1-1~deb12u11:115.3.1-1
Mozilla Thunderbird<78.10
78.10
Mozilla Firefox<88.0
Mozilla Firefox ESR<78.10
Mozilla Thunderbird<78.10
Mozilla Firefox<88
88
Mozilla Firefox ESR<78.10
78.10
Event History
Apr 19, 2021
CVE Published
via Mozilla·12:00 AM
Jun 24, 2021
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
DescriptionWeakness
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-23994?
CVE-2021-23994 has a medium severity level due to the potential for memory corruption and out-of-bounds write issues.
2
How do I fix CVE-2021-23994?
To fix CVE-2021-23994, update Mozilla Thunderbird and Firefox ESR to version 78.10 or later.
3
What software is affected by CVE-2021-23994?
CVE-2021-23994 affects Mozilla Thunderbird versions earlier than 78.10 and Firefox ESR versions earlier than 78.10.
4
Can CVE-2021-23994 lead to exploitation?
Yes, CVE-2021-23994 can potentially lead to exploitation through memory corruption vulnerabilities.
5
Is there a specific version of Firefox that resolves CVE-2021-23994?
Yes, upgrading to Firefox version 88 or later will resolve CVE-2021-23994.