First published: Tue Jun 01 2021(Updated: )
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <78.11 | 78.11 |
Mozilla Firefox | <89 | 89 |
Mozilla Thunderbird | <78.11 | 78.11 |
Mozilla Firefox | <89.0 | |
Mozilla Firefox ESR | <78.11 | |
Mozilla Thunderbird | <78.11 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2021-29964 is medium (4 out of 10).
CVE-2021-29964 affects Thunderbird on Windows and can lead to an out-of-bounds read.
No, Thunderbird is not the only affected software by CVE-2021-29964. It also affects Firefox ESR and Firefox versions up to 89.
To fix CVE-2021-29964, update Thunderbird to version 78.11 or later for Thunderbird, and update Firefox to version 78.11 or later for Firefox ESR, or version 89 or later for Firefox.
You can find more information about CVE-2021-29964 in the Mozilla advisory: https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/