A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbirdUpgrade firefox | Aug 22, 2024 | Dec 8, 2021 |
| Centos_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade firefox-debuginfo | Feb 28, 2022 | Dec 8, 2021 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Dec 30, 2021 | Dec 8, 2021 |
| Mfsa2021 43 | — | Upgrade to Mozilla Firefox version 93.0 | Dec 8, 2021 | Oct 5, 2021 |
| Mfsa2021 49 | — | Upgrade to Mozilla Firefox ESR version 91.3Upgrade to the latest version of Mozilla Firefox | Dec 8, 2021 | Nov 2, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.3Upgrade to the latest version of Mozilla Thunderbird | Dec 8, 2021 | Nov 3, 2021 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoUpgrade firefox-debuginfoNo solution existsUpgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade thunderbird | Feb 28, 2022 | Dec 8, 2021 |
| Rocky_linux | — | Upgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade thunderbird | Mar 12, 2024 | Dec 8, 2021 |
| Ubuntu | — | Upgrade thunderbird | Jan 22, 2022 | Dec 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub