CVE-2021-29976
Summary
| CVE | CVE-2021-29976 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-05 20:15:00 UTC |
| Updated | 2022-12-09 19:07:00 UTC |
| Description | Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159302 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-2741)
- 159303 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-2743)
- 159321 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-2881)
- 159323 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-2883)
- 178705 Debian Security Update for firefox-esr (DSA 4939-1)
- 178706 Debian Security Update for thunderbird (DSA 4940-1)
- 178708 Debian Security Update for firefox-esr (DLA 2709-1)
- 178715 Debian Security Update for thunderbird (DLA 2711-1)
- 179926 Debian Security Update for firefox-esrthunderbird (CVE-2021-29976)
- 198479 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5058-1)
- 198481 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5058-1)
- 198483 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5058-1)
- 239474 Red Hat Update for firefox (RHSA-2021:2743)
- 239475 Red Hat Update for firefox (RHSA-2021:2742)
- 239476 Red Hat Update for firefox (RHSA-2021:2741)
- 239477 Red Hat Update for firefox (RHSA-2021:2740)
- 239507 Red Hat Update for thunderbird (RHSA-2021:2914)
- 239508 Red Hat Update for thunderbird (RHSA-2021:2883)
- 239509 Red Hat Update for thunderbird (RHSA-2021:2882)
- 239510 Red Hat Update for thunderbird (RHSA-2021:2881)
- 257098 CentOS Security Update for firefox (CESA-2021:2741)
- 352834 Amazon Linux Security Advisory for thunderbird: ALAS2-2021-1709
- 375712 Mozilla Firefox Multiple Vulnerabilities (MFSA2021-28)
- 375716 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-29)
- 375717 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-30)
- 501550 Alpine Linux Security Update for firefox-esr
- 501616 Alpine Linux Security Update for mozjs78
- 502079 Alpine Linux Security Update for firefox
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 503850 Alpine Linux Security Update for firefox
- 506260 Alpine Linux Security Update for thunderbird
- 710574 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202202-03)
- 710585 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202208-14)
- 750838 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:2389-1)
- 750854 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:1066-1)
- 750862 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:2393-1)
- 750883 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:2458-1)
- 750898 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:2478-1)
- 750916 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1091-1)
- 940194 AlmaLinux Security Update for firefox (ALSA-2021:2743)
- 940333 AlmaLinux Security Update for thunderbird (ALSA-2021:2883)
- 960706 Rocky Linux Security Update for firefox (RLSA-2021:2743)