Lucene search

K
archlinuxArchLinuxASA-202109-2
HistorySep 14, 2021 - 12:00 a.m.

[ASA-202109-2] firefox: multiple issues

2021-09-1400:00:00
security.archlinux.org
19
firefox
multiple issues
arbitrary code execution
insufficient validation
remote attacker
crafted web content
memory safety bugs
http
https

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.5%

Arch Linux Security Advisory ASA-202109-2

Severity: High
Date : 2021-09-14
CVE-ID : CVE-2021-38491 CVE-2021-38494
Package : firefox
Type : multiple issues
Remote : Yes
Link : https://security.archlinux.org/AVG-2350

Summary

The package firefox before version 92.0-1 is vulnerable to multiple
issues including arbitrary code execution and insufficient validation.

Resolution

Upgrade to 92.0-1.

pacman -Syu “firefox>=92.0-1”

The problems have been fixed upstream in version 92.0.

Workaround

None.

Description

  • CVE-2021-38491 (insufficient validation)

In Firefox before version 92, mixed-content checks were unable to
analyze opaque origins which led to some mixed content being loaded.

  • CVE-2021-38494 (arbitrary code execution)

Mozilla developers reported memory safety bugs present in Firefox 91.
Some of these bugs showed evidence of memory corruption and Mozilla
presumes that with enough effort some of these could have been
exploited to run arbitrary code.

Impact

A remote attacker could execute arbitrary code through crafted web
content, or load content over HTTP on a web page otherwise served
through HTTPS.

References

https://www.mozilla.org/security/advisories/mfsa2021-38/
https://bugzilla.mozilla.org/show_bug.cgi?id=1551886
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1723920%2C1725638
https://security.archlinux.org/CVE-2021-38491
https://security.archlinux.org/CVE-2021-38494

OSVersionArchitecturePackageVersionFilename
ArchLinuxanyanyfirefox< 92.0-1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.5%