A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbirdUpgrade firefox | Aug 22, 2024 | Dec 8, 2021 |
| Centos_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade firefox-debugsourceUpgrade firefoxUpgrade firefox-debuginfoUpgrade thunderbird-debugsource | Feb 28, 2022 | Dec 8, 2021 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Dec 30, 2021 | Dec 8, 2021 |
| Mfsa2021 43 | — | Upgrade to Mozilla Firefox version 93.0 | Dec 8, 2021 | Oct 5, 2021 |
| Mfsa2021 49 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 91.3 | Dec 8, 2021 | Nov 2, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.3Upgrade to the latest version of Mozilla Thunderbird | Dec 8, 2021 | Nov 3, 2021 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoNo solution existsUpgrade firefoxUpgrade thunderbird | Feb 28, 2022 | Dec 8, 2021 |
| Rocky_linux | — | Upgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade thunderbirdUpgrade firefox-debugsource | Mar 12, 2024 | Dec 8, 2021 |
| Ubuntu | — | Upgrade thunderbird | Jan 22, 2022 | Dec 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub