A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade thunderbird | Aug 22, 2024 | Dec 8, 2021 |
| Centos_linux | — | Upgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade thunderbird | Feb 28, 2022 | Dec 8, 2021 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Dec 30, 2021 | Dec 8, 2021 |
| Mfsa2021 43 | — | Upgrade to Mozilla Firefox version 93.0 | Dec 8, 2021 | Oct 5, 2021 |
| Mfsa2021 49 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 91.3 | Dec 8, 2021 | Nov 2, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.3Upgrade to the latest version of Mozilla Thunderbird | Dec 8, 2021 | Nov 3, 2021 |
| Redhat_linux | — | No solution existsUpgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird | Feb 28, 2022 | Dec 8, 2021 |
| Rocky_linux | — | Upgrade firefox-debugsourceUpgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird-debuginfo | Mar 12, 2024 | Dec 8, 2021 |
| Ubuntu | — | Upgrade thunderbird | Jan 22, 2022 | Dec 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub