CVE-2021-29970
Summary
| CVE | CVE-2021-29970 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-05 20:15:00 UTC |
| Updated | 2022-12-09 19:04:00 UTC |
| Description | A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90. |
Risk And Classification
Problem Types: CWE-787 | CWE-416
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | MISC | bugzilla.mozilla.org | |
| Mozilla Thunderbird: Multiple Vulnerabilities (GLSA 202208-14) — Gentoo security | GENTOO | security.gentoo.org | |
| Security Vulnerabilities fixed in Firefox ESR 78.12 — Mozilla | MISC | www.mozilla.org | |
| Security Vulnerabilities fixed in Firefox 90 — Mozilla | MISC | www.mozilla.org | |
| Security Vulnerabilities fixed in Thunderbird 78.12 — Mozilla | MISC | www.mozilla.org | |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 202202-03) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159302 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-2741)
- 159303 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-2743)
- 159321 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-2881)
- 159323 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-2883)
- 178705 Debian Security Update for firefox-esr (DSA 4939-1)
- 178706 Debian Security Update for thunderbird (DSA 4940-1)
- 178708 Debian Security Update for firefox-esr (DLA 2709-1)
- 178715 Debian Security Update for thunderbird (DLA 2711-1)
- 180372 Debian Security Update for firefox-esrthunderbird (CVE-2021-29970)
- 198479 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5058-1)
- 198481 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5058-1)
- 198483 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5058-1)
- 239474 Red Hat Update for firefox (RHSA-2021:2743)
- 239475 Red Hat Update for firefox (RHSA-2021:2742)
- 239476 Red Hat Update for firefox (RHSA-2021:2741)
- 239477 Red Hat Update for firefox (RHSA-2021:2740)
- 239507 Red Hat Update for thunderbird (RHSA-2021:2914)
- 239508 Red Hat Update for thunderbird (RHSA-2021:2883)
- 239509 Red Hat Update for thunderbird (RHSA-2021:2882)
- 239510 Red Hat Update for thunderbird (RHSA-2021:2881)
- 257098 CentOS Security Update for firefox (CESA-2021:2741)
- 352834 Amazon Linux Security Advisory for thunderbird: ALAS2-2021-1709
- 375712 Mozilla Firefox Multiple Vulnerabilities (MFSA2021-28)
- 375716 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-29)
- 375717 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-30)
- 501550 Alpine Linux Security Update for firefox-esr
- 502079 Alpine Linux Security Update for firefox
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 503850 Alpine Linux Security Update for firefox
- 506260 Alpine Linux Security Update for thunderbird
- 710574 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202202-03)
- 710585 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202208-14)
- 750838 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:2389-1)
- 750854 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:1066-1)
- 750862 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:2393-1)
- 750883 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:2458-1)
- 750898 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:2478-1)
- 750916 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1091-1)
- 940194 AlmaLinux Security Update for firefox (ALSA-2021:2743)
- 940333 AlmaLinux Security Update for thunderbird (ALSA-2021:2883)
- 960706 Rocky Linux Security Update for firefox (RLSA-2021:2743)