CVE-2021-23953

high
Published 2021-01-27 Β· Modified 2021-01-28
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description Mozilla: Cross-origin information leakage via redirected PDF requests CVSS v3: 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7firefox-0:78.7.0-2.el7_9RHSA-2021:02902021-01-28T00:00:00Z Red Hat Enterprise Linux 7thunderbird-0:78.7.0-1.el7_9RHSA-2021:02972021-01-28T00:00:00Z Red Hat Enterprise Linux…

Description

Mozilla: Cross-origin information leakage via redirected PDF requests

CVSS v3: 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7firefox-0:78.7.0-2.el7_9RHSA-2021:02902021-01-28T00:00:00Z
Red Hat Enterprise Linux 7thunderbird-0:78.7.0-1.el7_9RHSA-2021:02972021-01-28T00:00:00Z
Red Hat Enterprise Linux 8firefox-0:78.7.0-2.el8_3RHSA-2021:02882021-01-27T00:00:00Z
Red Hat Enterprise Linux 8thunderbird-0:78.7.0-1.el8_3RHSA-2021:02982021-01-28T00:00:00Z
Red Hat Enterprise Linux 8.1 Extended Update Supportfirefox-0:78.7.0-2.el8_1RHSA-2021:02852021-01-27T00:00:00Z
Red Hat Enterprise Linux 8.1 Extended Update Supportthunderbird-0:78.7.0-1.el8_1RHSA-2021:03972021-02-03T00:00:00Z
Red Hat Enterprise Linux 8.2 Extended Update Supportfirefox-0:78.7.0-2.el8_2RHSA-2021:02892021-01-27T00:00:00Z
Red Hat Enterprise Linux 8.2 Extended Update Supportthunderbird-0:78.7.0-1.el8_2RHSA-2021:02992021-01-28T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope

Apply commands

bash fix
Apply RHSA-2021:0290 for Red Hat Enterprise Linux 7
yum update -y firefox
# or:
dnf upgrade -y firefox

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 78.7.0-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 78.7.0esr-1
sid Fixed 85.0-1
forky Fixed 78.7.0esr-1
bullseye Fixed 78.7.0esr-1
bookworm Fixed 78.7.0esr-1
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.