CVE-2021-38500
Summary
| CVE | CVE-2021-38500 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-03 01:15:00 UTC |
| Updated | 2022-03-17 19:36:00 UTC |
| Description | Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug List | MISC | bugzilla.mozilla.org | |
| Security Vulnerabilities fixed in Firefox ESR 78.15 — Mozilla | MISC | www.mozilla.org | |
| Security Vulnerabilities fixed in Firefox ESR 91.2 — Mozilla | MISC | www.mozilla.org | |
| Security Vulnerabilities fixed in Firefox 93 — Mozilla | MISC | www.mozilla.org | |
| 404: Page Not Found | MISC | www.mozilla.org | |
| Security Vulnerabilities fixed in Thunderbird 91.2 — Mozilla | MISC | www.mozilla.org | |
| Debian -- Security Information -- DSA-5034-1 thunderbird | DEBIAN | www.debian.org | |
| [SECURITY] [DLA 2874-1] thunderbird security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159412 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-3755)
- 159428 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-3791)
- 159429 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-3838)
- 159430 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-3841)
- 178822 Debian Security Update for firefox-esr (DSA 4981-1)
- 178831 Debian Security Update for firefox-esr (DLA 2782-1)
- 178983 Debian Security Update for thunderbird (DSA 5034-1)
- 178986 Debian Security Update for thunderbird (DLA 2874-1)
- 183261 Debian Security Update for firefox-esrthunderbird (CVE-2021-38500)
- 198534 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5107-1)
- 198559 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5132-1)
- 198641 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)
- 239664 Red Hat Update for firefox (RHSA-2021:3757)
- 239665 Red Hat Update for firefox (RHSA-2021:3756)
- 239666 Red Hat Update for firefox (RHSA-2021:3755)
- 239677 Red Hat Update for firefox (RHSA-2021:3791)
- 239682 Red Hat Update for thunderbird (RHSA-2021:3841)
- 239683 Red Hat Update for thunderbird (RHSA-2021:3840)
- 239684 Red Hat Update for thunderbird (RHSA-2021:3839)
- 239685 Red Hat Update for thunderbird (RHSA-2021:3838)
- 257116 CentOS Security Update for firefox (CESA-2021:3791)
- 257126 CentOS Security Update for thunderbird (CESA-2021:3841)
- 296066 Oracle Solaris 11.4 Support Repository Update (SRU) 40.107.3 Missing (CPUOCT2021)
- 353982 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1818
- 375940 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-44)
- 375943 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-45)
- 375945 Mozilla Firefox Multiple Vulnerabilities (MFSA2021-43)
- 375958 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-46)
- 375959 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-47)
- 501553 Alpine Linux Security Update for firefox-esr
- 501619 Alpine Linux Security Update for mozjs78
- 502069 Alpine Linux Security Update for firefox-esr
- 502081 Alpine Linux Security Update for firefox
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 503852 Alpine Linux Security Update for firefox
- 504812 Alpine Linux Security Update for firefox-esr
- 506260 Alpine Linux Security Update for thunderbird
- 751210 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3331-1)
- 751226 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3331-1)
- 751230 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3446-1)
- 751237 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3451-1)
- 751246 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:1367-1)
- 751542 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:4150-1)
- 751566 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1635-1)
- 940182 AlmaLinux Security Update for firefox (ALSA-2021:3755)
- 940268 AlmaLinux Security Update for thunderbird (ALSA-2021:3838)
- 960080 Rocky Linux Security Update for firefox (RLSA-2021:3755)