Race condition in Mozilla Firefox - CVE-2021-29952

 

Race condition in Mozilla Firefox - CVE-2021-29952

Published: May 5, 2021


Vulnerability identifier: #VU52899
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29952
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Web Render components. A remote attacker can create a specially crafted web page, trick the victim into opening it and execute arbitrary code on the system.


Affected software

Mozilla Firefox
Arch Linux
Ubuntu
Fedora
Firefox for Android
firefox
firefox (Ubuntu package)

How to mitigate CVE-2021-29952

Install updates from vendor's website.

Mozilla Firefox - update to 88.0.1
Firefox for Android - update to 88.1.3
firefox - addressed in versions stable-3420210510090803.1, 88.0.1-1.fc33, 88.0.1-1.fc34
firefox (Ubuntu package) - addressed in versions 88.0.1+build1-0ubuntu0.18.04.2, 88.0.1+build1-0ubuntu0.20.04.2, 88.0.1+build1-0ubuntu0.20.10.2, 88.0.1+build1-0ubuntu0.21.04.2

External References

Related Security Bulletins