Input validation error in Firefox ESR and Mozilla Firefox - CVE-2021-38492
Published: September 7, 2021 / Updated: September 8, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when delegating navigations to the operating system. Firefox accept the mk scheme, which allows a remote attacker to launch pages and execute scripts in Internet Explorer in unprivileged mode.
Affected software
Mozilla Firefox
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Workstation Extension
Mozilla Thunderbird
MozillaFirefox
MozillaFirefox-debuginfo
MozillaFirefox-debugsource
MozillaFirefox-devel
MozillaFirefox-translations-common
MozillaFirefox-translations-other
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
MozillaFirefox-branding-SLE
mail-client/thunderbird-bin
mail-client/thunderbird
MozillaFirefox-branding-SLED
How to mitigate CVE-2021-38492
Mozilla Firefox - update to 92.0
Mozilla Thunderbird - addressed in versions 78.14.0, 91.1.0
MozillaFirefox - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-debuginfo - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-debugsource - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-devel - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-translations-common - addressed in versions 91.1.0-112.71.1, 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-112.104.1, 91.9.0-150000.150.34.1
MozillaFirefox-translations-other - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.9.0-150000.150.34.1
MozillaThunderbird - update to 91.4.0-8.45.2
MozillaThunderbird-debuginfo - update to 91.4.0-8.45.2
MozillaThunderbird-debugsource - update to 91.4.0-8.45.2
MozillaThunderbird-translations-common - update to 91.4.0-8.45.2
MozillaThunderbird-translations-other - update to 91.4.0-8.45.2
MozillaFirefox-branding-SLE - addressed in versions 91-4.19.1, 91-9.5.1, 91-35.6.6
mail-client/thunderbird-bin - update to 91.12.0
mail-client/thunderbird - update to 91.12.0
MozillaFirefox-branding-SLED - update to 91-21.18.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- SUSE Linux Enterprise Server 11 update for Mozilla Firefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox, rust-cbindgen
- Gentoo update for Mozilla Thunderbird
- SUSE update for MozillaThunderbird
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox