CVE-2021-43534: High severity thunderbird vulnerability
Mozilla developers and community members Christian Holler, Valentin Gosu, and Andrew McCreight reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
Mozilla developers and community members Christian Holler, Valentin Gosu, and Andrew McCreight reported memory safety bugs present in Thunderbird 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-43534?
The severity of CVE-2021-43534 is high.
Which versions of Firefox are affected by CVE-2021-43534?
Firefox versions up to and excluding 94 are affected by CVE-2021-43534.
How can I fix CVE-2021-43534 in Firefox?
To fix CVE-2021-43534 in Firefox, update to version 94 or higher.
Which versions of Firefox ESR are affected by CVE-2021-43534?
Firefox ESR versions up to and excluding 91.3 are affected by CVE-2021-43534.
How can I fix CVE-2021-43534 in Firefox ESR?
To fix CVE-2021-43534 in Firefox ESR, update to version 91.3 or higher.