CVE-2021-38501
Summary
| CVE | CVE-2021-38501 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-03 01:15:00 UTC |
| Updated | 2021-11-04 19:29:00 UTC |
| Description | Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Vulnerabilities fixed in Firefox ESR 91.2 — Mozilla | MISC | www.mozilla.org | |
| Security Vulnerabilities fixed in Firefox 93 — Mozilla | MISC | www.mozilla.org | |
| Bug List | MISC | bugzilla.mozilla.org | |
| Security Vulnerabilities fixed in Thunderbird 91.2 — Mozilla | MISC | www.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159412 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-3755)
- 159428 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-3791)
- 159429 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-3838)
- 159430 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-3841)
- 198534 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5107-1)
- 198559 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5132-1)
- 198641 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)
- 239664 Red Hat Update for firefox (RHSA-2021:3757)
- 239665 Red Hat Update for firefox (RHSA-2021:3756)
- 239666 Red Hat Update for firefox (RHSA-2021:3755)
- 239677 Red Hat Update for firefox (RHSA-2021:3791)
- 239682 Red Hat Update for thunderbird (RHSA-2021:3841)
- 239683 Red Hat Update for thunderbird (RHSA-2021:3840)
- 239684 Red Hat Update for thunderbird (RHSA-2021:3839)
- 239685 Red Hat Update for thunderbird (RHSA-2021:3838)
- 257116 CentOS Security Update for firefox (CESA-2021:3791)
- 257126 CentOS Security Update for thunderbird (CESA-2021:3841)
- 296066 Oracle Solaris 11.4 Support Repository Update (SRU) 40.107.3 Missing (CPUOCT2021)
- 353982 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1818
- 375943 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-45)
- 375945 Mozilla Firefox Multiple Vulnerabilities (MFSA2021-43)
- 375959 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-47)
- 502069 Alpine Linux Security Update for firefox-esr
- 502081 Alpine Linux Security Update for firefox
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 503852 Alpine Linux Security Update for firefox
- 504812 Alpine Linux Security Update for firefox-esr
- 506260 Alpine Linux Security Update for thunderbird
- 751210 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3331-1)
- 751226 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3331-1)
- 751230 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3446-1)
- 751237 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3451-1)
- 751246 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:1367-1)
- 751542 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:4150-1)
- 751566 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1635-1)
- 940182 AlmaLinux Security Update for firefox (ALSA-2021:3755)
- 940268 AlmaLinux Security Update for thunderbird (ALSA-2021:3838)
- 960080 Rocky Linux Security Update for firefox (RLSA-2021:3755)