CVE-2021-29964Out-of-bounds Read in Mozilla Firefox

CWE-125Out-of-bounds Read9 documents7 sources
Severity
7.1HIGHNVD
EPSS
0.3%
top 44.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateMay 24

Description

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified89
NVDmozilla/firefox< 89.0
CVEListV5mozilla/firefox_esrunspecified78.11
NVDmozilla/firefox_esr< 78.11
CVEListV5mozilla/thunderbirdunspecified78.11

🔴Vulnerability Details

3
GHSA
GHSA-6mgf-v5gc-vgc7: A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read2022-05-24
OSV
CVE-2021-29964: A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read2021-06-24
CVEList
CVE-2021-29964: A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read2021-06-24

📋Vendor Advisories

5
Red Hat
Mozilla: Out of bounds-read when parsing a `WM_COPYDATA` message2021-06-01
Debian
CVE-2021-29964: firefox - A locally-installed hostile program could send `WM_COPYDATA` messages that Firef...2021
Mozilla
Mozilla Foundation Security Advisory 2021-24: CVE-2021-29964
Mozilla
Mozilla Foundation Security Advisory 2021-23: CVE-2021-29964
Mozilla
Mozilla Foundation Security Advisory 2021-26: CVE-2021-29964
CVE-2021-29964 — Out-of-bounds Read in Mozilla Firefox | cvebase