CVE-2021-29991
Summary
| CVE | CVE-2021-29991 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-03 01:15:00 UTC |
| Updated | 2021-11-04 21:01:00 UTC |
| Description | Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198470 Ubuntu Security Notification for Firefox Vulnerability (USN-5047-1)
- 198641 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)
- 296066 Oracle Solaris 11.4 Support Repository Update (SRU) 40.107.3 Missing (CPUOCT2021)
- 375824 Mozilla Firefox Header Splitting Vulnerability(MFSA2021-37)
- 375825 Mozilla Thunderbird Header Splitting Vulnerability(MFSA2021-37)
- 502080 Alpine Linux Security Update for firefox
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 503851 Alpine Linux Security Update for firefox
- 506260 Alpine Linux Security Update for thunderbird
- 751210 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3331-1)
- 751226 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3331-1)
- 751237 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3451-1)
- 751246 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:1367-1)
- 751369 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3191-1)
- 751542 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:4150-1)
- 751566 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1635-1)
- 752111 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:1582-1)
- 752113 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:1577-1)