Resource management error in Mozilla Firefox - CVE-2021-23958
Published: January 26, 2021
Vulnerability identifier: #VU50028
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23958
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of internal resources within the application. A remote attacker can confuse the browser into transferring a screen sharing state into another tab, which would leak unintended information.
Affected software
Mozilla Firefox
Gentoo Linux
Arch Linux
Ubuntu
firefox (Ubuntu package)
Gentoo Linux
Arch Linux
Ubuntu
firefox (Ubuntu package)
How to mitigate CVE-2021-23958
Install updates from vendor's website.
Mozilla Firefox - update to 85.0
firefox (Ubuntu package) - addressed in versions 85.0+build1-0ubuntu0.16.04.1, 85.0+build1-0ubuntu0.18.04.1, 85.0+build1-0ubuntu0.20.04.1, 85.0+build1-0ubuntu0.20.10.1
firefox (Ubuntu package) - addressed in versions 85.0+build1-0ubuntu0.16.04.1, 85.0+build1-0ubuntu0.18.04.1, 85.0+build1-0ubuntu0.20.04.1, 85.0+build1-0ubuntu0.20.10.1