Resource management error in Mozilla Firefox - CVE-2021-23963

 

Resource management error in Mozilla Firefox - CVE-2021-23963

Published: January 26, 2021


Vulnerability identifier: #VU50032
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23963
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission.


Affected software

Mozilla Firefox
Gentoo Linux
Arch Linux
Ubuntu
firefox (Ubuntu package)

How to mitigate CVE-2021-23963

Install updates from vendor's website.

Mozilla Firefox - update to 85.0
firefox (Ubuntu package) - addressed in versions 85.0+build1-0ubuntu0.16.04.1, 85.0+build1-0ubuntu0.18.04.1, 85.0+build1-0ubuntu0.20.04.1, 85.0+build1-0ubuntu0.20.10.1

External References

Related Security Bulletins