CVE-2021-29964

Description

A locally-installed hostile program could send WM_COPYDATA messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.324

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Mozilla Firefox (x64) (89.0)Windows
Multiple vulnerabilities fixed in Mozilla Firefox (89.0)Windows
Vulnerabilities CVE-2021-29964,CVE-2021-29967 are fixed in Mozilla Firefox ESR (x64) (78.11.0)Windows
Vulnerabilities CVE-2021-29964,CVE-2021-29967 are fixed in Mozilla Firefox ESR (78.11.0)Windows
Vulnerabilities CVE-2021-29964,CVE-2021-29967 are fixed in Mozilla Thunderbird (78.11.0)Windows
Vulnerabilities CVE-2021-29964,CVE-2021-29967 are fixed in Mozilla Thunderbird (x64) (78.11.0)Windows
Vulnerabilities CVE-2021-29964 are affected in Mozilla Firefox (x64) 88.9Windows
Vulnerabilities CVE-2021-29964 are affected in Mozilla Firefox ESR (x64) 78.10Windows
Vulnerabilities CVE-2021-29964 are affected in Mozilla Firefox ESR 78.10Windows
Vulnerabilities CVE-2021-29964 are affected in Mozilla Thunderbird 78.10Windows
Vulnerabilities CVE-2021-29964 are affected in Mozilla_Firefox 88.9Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (89.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (89.0.2)Mac
Vulnerabilities CVE-2021-29964,CVE-2021-29967 are fixed in Mozilla Thunderbird For Mac (78.11.0)Mac
Vulnerabilities CVE-2021-29964,CVE-2021-29967 are fixed in Mozilla Firefox ESR for MAC 78.11.0Mac
Vulnerabilities CVE-2021-29963,CVE-2021-29964,CVE-2021-29965 are affected in Mozilla Firefox for Mac 88.9Mac
Vulnerabilities CVE-2021-29964 are affected in Firefox ESR for Mac 78.10Mac
Vulnerabilities CVE-2021-29964 are affected in Mozilla Firefox for Mac 78.10Mac
Vulnerabilities CVE-2021-29964 are affected in Mozilla Thunderbird for Mac 78.10Mac
SUSE-SU-2021:1886-1(SUSE Linux Enterprise Server 12-SP5 ) MozillaFirefox-78.11.0-112.62.1.x86_64.rpmLinux
SUSE-SU-2021:1886-1(SUSE Linux Enterprise Server 12-SP5 ) MozillaFirefox-debuginfo-78.11.0-112.62.1.x86_64.rpmLinux
SUSE-SU-2021:1886-1(SUSE Linux Enterprise Server 12-SP5 ) MozillaFirefox-debugsource-78.11.0-112.62.1.x86_64.rpmLinux
SUSE-SU-2021:1886-1(SUSE Linux Enterprise Server 12-SP5 ) MozillaFirefox-devel-78.11.0-112.62.1.x86_64.rpmLinux
SUSE-SU-2021:1886-1(SUSE Linux Enterprise Server 12-SP5 ) MozillaFirefox-translations-common-78.11.0-112.62.1.x86_64.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-319856Mozilla Firefox (x64) (89.0)
PATCH-319855Mozilla Firefox (89.0)
PATCH-319858Mozilla Firefox ESR (x64) (78.11.0)
PATCH-319857Mozilla Firefox ESR (78.11.0)
PATCH-319890Mozilla Thunderbird (78.11.0)
PATCH-319891Mozilla Thunderbird (x64) (78.11.0)
PATCH-334458Mozilla Firefox (x64) (120.0)
PATCH-334457Mozilla Firefox (120.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-611353Mozilla Thunderbird For Mac (128.12.0)
PATCH-607001Mozilla Firefox ESR for MAC 115.9.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234