CERT-In Vulnerability Note
CIVN-2021-0228
Multiple Vulnerabilities in Mozilla Products
Original Issue Date:September 14, 2021
Severity Rating: HIGH
Software Affected
- Mozilla Firefox for Android versions prior to92
- Mozilla Firefox ESR versions prior to 78.14
- Mozilla Firefox ESR versions prior to 91.1
- Mozilla Thunderbird for Windows versions prior to 78.14
- Mozilla Thunderbird for Windows versions prior to 91.1
Overview
Multiple vulnerabilities have been reported in Mozilla products which could allow a remote attacker to bypass security restrictions, execute arbitrary code, and cause denial of service attack on the targeted system.
Description
These vulnerabilities exist in Mozilla products due to memory corruption issues and a bug in delegating navigations to the operating system. A remote attacker could exploit this vulnerability by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Upgrade to Firefox for Android version 92, Firefox ESR 78.14, Firefox ESR 91.1, Thunderbird for Windows versions 78.14 and Thunderbird 91.1
Vendor Information
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2021-42/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-41/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-40/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-39/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-38/
References
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2021-42/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-41/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-40/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-39/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-38/
CVE Name
CVE-2021-29993
CVE-2021-38491
CVE-2021-38492
CVE-2021-38493
CVE-2021-38494
CVE-2021-38495
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|