The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade librewolf | Aug 22, 2024 | Feb 26, 2021 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | May 3, 2021 | Feb 26, 2021 |
| Mfsa2021 07 | — | Upgrade to Mozilla Firefox version 86.0 | Feb 24, 2021 | Feb 23, 2021 |
| Ubuntu | — | Upgrade firefox | Feb 27, 2021 | Feb 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub