REDHAT-BUG-2489211: Medium severity Mozilla Firefox ESR vulnerability
Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 152 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.12 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Mozilla Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.12
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2489211?
The severity of REDHAT-BUG-2489211 is classified as medium with a score of 4.
How do I fix REDHAT-BUG-2489211?
To fix REDHAT-BUG-2489211, updating to the latest versions of Firefox ESR, Firefox, Thunderbird ESR, or Thunderbird is necessary.
What systems are affected by REDHAT-BUG-2489211?
REDHAT-BUG-2489211 affects Mozilla Firefox ESR 140.11, Mozilla Thunderbird ESR 140.11, Mozilla Firefox 151, and Mozilla Thunderbird 151.
What potential issues does REDHAT-BUG-2489211 pose?
REDHAT-BUG-2489211 poses the potential risk of memory corruption that could lead to arbitrary code execution.
Is there any known exploit for REDHAT-BUG-2489211?
There are no confirmed exploits for REDHAT-BUG-2489211, but the nature of the memory safety bugs suggests the possibility with sufficient effort.