CVE-2021-43535

Description

A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.63

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2021-43535 are affected in Mozilla Firefox (x64) 92.0Windows
Vulnerability CVE-2021-43535 are affected in Mozilla Firefox 92.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 92.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 92.99Windows
Vulnerabilities CVE-2021-43535 are affected in Mozilla Firefox (x64) 91.2.99Windows
Vulnerabilities CVE-2021-43535 are affected in Mozilla_Firefox 91.2.99Windows
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 92.0Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 91.2Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 91.2Mac
Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 91.2Mac
firefox-esr security update(DSA-5026-1) firefox-esr_91.4.1esr-1~deb11u1_amd64.debLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_i386.debLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb10u1_amd64.debLinux
thunderbird security update(DSA-5034-1) thunderbird_91.4.1-1~deb11u1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-5248-1) thunderbird_91.5.0+build1-0ubuntu0.20.04.1_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-321584Mozilla Firefox (x64) (92.0.1)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234