A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade thunderbird | Aug 22, 2024 | Dec 8, 2021 |
| Centos_linux | — | Upgrade thunderbirdUpgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade firefox-debugsource | Feb 28, 2022 | Dec 8, 2021 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Dec 30, 2021 | Dec 8, 2021 |
| Mfsa2021 43 | — | Upgrade to Mozilla Firefox version 93.0 | Dec 8, 2021 | Oct 5, 2021 |
| Mfsa2021 49 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 91.3 | Dec 8, 2021 | Nov 2, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.3Upgrade to the latest version of Mozilla Thunderbird | Dec 8, 2021 | Nov 3, 2021 |
| Redhat_linux | — | Upgrade firefoxUpgrade thunderbirdNo solution existsUpgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | Feb 28, 2022 | Dec 8, 2021 |
| Rocky_linux | — | Upgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade thunderbirdUpgrade firefox-debugsource | Mar 12, 2024 | Dec 8, 2021 |
| Ubuntu | — | Upgrade thunderbird | Jan 22, 2022 | Dec 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub