Multiple vulnerabilities in Mozilla Thunderbird



Published: 2021-03-23
Risk High
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2021-23981
CVE-2021-23982
CVE-2021-23984
CVE-2021-23987
CWE-ID CWE-125
CWE-200
CWE-451
CWE-119
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Mozilla Thunderbird
Client/Desktop applications / Messaging software

Vendor Mozilla

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

1) Out-of-bounds read

EUVDB-ID: #VU51661

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2021-23981

CWE-ID: CWE-125 - Out-of-bounds Read

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition during texture upload of a Pixel Buffer Object in WebGL. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.

Mitigation

Install updates from vendor' website.

Vulnerable software versions

Mozilla Thunderbird: 78.0 - 78.8.1, 68.0 - 68.12.1, 60.0 - 60.9.1


CPE2.3 External links

http://www.mozilla.org/en-US/security/advisories/mfsa2021-12/

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

2) Information disclosure

EUVDB-ID: #VU51662

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2021-23982

CWE-ID: CWE-200 - Information Exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the way Firefox handles requests to internal hosts. Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections.

Mitigation

Install updates from vendor' website.

Vulnerable software versions

Mozilla Thunderbird: 78.0 - 78.8.1, 68.0 - 68.12.1, 60.0 - 60.9.1


CPE2.3 External links

http://www.mozilla.org/en-US/security/advisories/mfsa2021-12/

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

3) Spoofing attack

EUVDB-ID: #VU51664

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2021-23984

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials.

Mitigation

Install updates from vendor' website.

Vulnerable software versions

Mozilla Thunderbird: 78.0 - 78.8.1, 68.0 - 68.12.1, 60.0 - 60.9.1


CPE2.3 External links

http://www.mozilla.org/en-US/security/advisories/mfsa2021-12/

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

4) Buffer overflow

EUVDB-ID: #VU51667

Risk: High

CVSSv3.1:

CVE-ID: CVE-2021-23987

CWE-ID: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor' website.

Vulnerable software versions

Mozilla Thunderbird: 78.0 - 78.8.1, 68.0 - 68.12.1, 60.0 - 60.9.1


CPE2.3 External links

http://www.mozilla.org/en-US/security/advisories/mfsa2021-12/

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###