Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23981

Опубликовано: 23 мар. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

The Mozilla Foundation Security Advisory describes this issue as: A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7firefoxFixedRHSA-2021:099225.03.2021
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2021:099625.03.2021
Red Hat Enterprise Linux 8firefoxFixedRHSA-2021:099025.03.2021
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2021:099325.03.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportfirefoxFixedRHSA-2021:099125.03.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportthunderbirdFixedRHSA-2021:099525.03.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportfirefoxFixedRHSA-2021:098925.03.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportthunderbirdFixedRHSA-2021:099425.03.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1942783Mozilla: Texture upload into an unbound backing buffer resulted in an out-of-bound read

EPSS

Процентиль: 64%
0.00461
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 5 лет назад

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.1
nvd
почти 5 лет назад

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.1
debian
почти 5 лет назад

A texture upload of a Pixel Buffer Object could have confused the WebG ...

CVSS3: 8.1
github
больше 3 лет назад

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Thunderbird < 78.9, and Firefox < 87.

suse-cvrf
почти 5 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 64%
0.00461
Низкий

7.5 High

CVSS3