Description
There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:
- Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these
bugs showed evidence of memory corruption and we presume that with enough effort some of these could have
been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and
Firefox ESR < 91.2. (CVE-2021-38501)
- crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in
Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in
the worker queue can be popped twice instead of other tasks that are forgotten and never popped. If tasks
are allocated on the heap, this can cause double free and a memory leak. If not, this still can cause a
logical bug. Crates using `Stealer::steal`, `Stealer::steal_batch`, or `Stealer::steal_batch_and_pop` are
affected by this issue. This has been fixed in crossbeam-deque 0.8.1 and 0.7.4. (CVE-2021-32810)
- During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in
memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15,
Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93. (CVE-2021-38496)
- Through use of reportValidity() and window.open(), a plain-text validation message could have been
overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability
affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2. (CVE-2021-38497)
- During process shutdown, a document could have caused a use-after-free of a languages service object,
leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93,
Thunderbird < 91.2, and Firefox ESR < 91.2. (CVE-2021-38498)
Plugin Details
Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 8/2/2021