First published: Tue Jul 13 2021(Updated: )
Mozilla developers Emil Ghitta, Tyson Smith, Valentin Gosu, Olli Pettay, and Randell Jesup reported memory safety bugs present in Firefox 89 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <78.12 | 78.12 |
<90 | 90 | |
<78.12 | 78.12 | |
<78.12 | 78.12 | |
Mozilla Firefox | <90.0 | |
Mozilla Firefox ESR | <78.12 | |
Mozilla Thunderbird | <78.12 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-29976 is classified as a high-severity vulnerability due to potential memory corruption issues.
To fix CVE-2021-29976, update to Firefox version 90 or later, or Firefox ESR version 78.12 or later.
CVE-2021-29976 affects Firefox 89, Firefox ESR 78.11, and earlier versions of these products.
Yes, although exploitation would require considerable effort due to memory safety issues involved.
CVE-2021-29976 was reported by Mozilla developers Emil Ghitta, Tyson Smith, Valentin Gosu, Olli Pettay, and Randell Jesup.