First published: Mon Apr 19 2021(Updated: )
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <88 | 88 |
Firefox | <88.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-23997 has a moderate severity rating due to the potential for exploitation leading to arbitrary code execution.
To fix CVE-2021-23997, update Mozilla Firefox to version 88 or later.
CVE-2021-23997 affects all versions of Mozilla Firefox prior to version 88.
Yes, CVE-2021-23997 could potentially be exploited remotely through crafted web content.
A use-after-free vulnerability like CVE-2021-23997 occurs when memory that has been freed is accessed, potentially leading to arbitrary code execution.