First published: Tue Oct 05 2021(Updated: )
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
<93 | 93 | |
<91.2 | 91.2 | |
Mozilla Thunderbird | <91.2 | 91.2 |
<91.2 | 91.2 | |
Mozilla Firefox | <93.0 | |
Mozilla Firefox ESR | <91.2 | |
Mozilla Thunderbird | <91.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-38498 is a vulnerability in Mozilla Thunderbird and Firefox that can cause a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash.
CVE-2021-38498 has a severity rating of medium.
CVE-2021-38498 affects Mozilla Thunderbird up to version 91.2, Firefox ESR up to version 91.2, and Firefox up to version 93.
To fix CVE-2021-38498, update Mozilla Thunderbird to version 91.2, Firefox ESR to version 91.2, or Firefox to version 93.
You can find more information about CVE-2021-38498 in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1729642), [Mozilla Security Advisory MFSAs](https://www.mozilla.org/en-US/security/advisories/mfsa2021-47/), [Mozilla Security Advisory MFSA2021-43](https://www.mozilla.org/en-US/security/advisories/mfsa2021-43/).