Resource management error in Firefox for Android - CVE-2021-29983

 

Resource management error in Firefox for Android - CVE-2021-29983

Published: August 10, 2021


Vulnerability identifier: #VU55681
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29983
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform clickjacking attack.

The vulnerability exists due to improper management of internal resources within the application. Firefox for Android can get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. A remote attacker can abuse this to trick the victim into revealing sensitive information.


Affected software

Firefox for Android
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Desktop Applications
MozillaFirefox
MozillaFirefox-debuginfo
MozillaFirefox-debugsource
MozillaFirefox-devel
MozillaFirefox-translations-common
MozillaFirefox-translations-other
MozillaFirefox-branding-SLE
MozillaFirefox-branding-SLED

How to mitigate CVE-2021-29983

Install updates from vendor's website.

Firefox for Android - update to 91.1.0
MozillaFirefox - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-debuginfo - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-debugsource - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-devel - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-translations-common - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-translations-other - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-150000.150.34.1
MozillaFirefox-branding-SLE - addressed in versions 91-4.19.1, 91-9.5.1, 91-35.6.6
MozillaFirefox-branding-SLED - update to 91-21.18.1

External References

Related Security Bulletins