Information disclosure in Mozilla Firefox and Firefox ESR - CVE-2021-38505

 

Information disclosure in Mozilla Firefox and Firefox ESR - CVE-2021-38505

Published: November 2, 2021


Vulnerability identifier: #VU57879
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38505
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to absence of support for a new feature in Windows 10 known as Cloud Clipboard that, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats, which were not implemented in previous versions of Firefox and Firefox ESR.


Affected software

Mozilla Firefox
Firefox ESR
SUSE CaaS Platform
SUSE Enterprise Storage
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Module for Desktop Applications
Mozilla Thunderbird
MozillaFirefox-translations-common
MozillaFirefox-devel
MozillaFirefox-debugsource
MozillaFirefox-debuginfo
MozillaFirefox
MozillaFirefox-translations-other
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other

How to mitigate CVE-2021-38505

Install updates from vendor's website.

Mozilla Firefox - update to 94.0
Firefox ESR - update to 91.3.0
Mozilla Thunderbird - update to 91.3.0
MozillaFirefox-translations-common - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-devel - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-debugsource - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-debuginfo - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-translations-other - addressed in versions 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaThunderbird - update to 91.4.0-8.45.2
MozillaThunderbird-debuginfo - update to 91.4.0-8.45.2
MozillaThunderbird-debugsource - update to 91.4.0-8.45.2
MozillaThunderbird-translations-common - update to 91.4.0-8.45.2
MozillaThunderbird-translations-other - update to 91.4.0-8.45.2

External References

Related Security Bulletins