Description:
Mozilla has published the advisories (MFSA 2021-23 and MFSA 2021-24) to address multiple vulnerabilities in Firefox browser. A remote attacker could entice a user running a vulnerable browser to visit a web page with specially crafted content to exploit the vulnerabilities.
Affected Systems:
- Firefox ESR Windows versions prior to version 78.11
- Firefox Windows versions prior to version 89
Impact:
Successful exploitation of the vulnerabilities could lead to arbitrary code execution, information disclosure, security feature bypass and spoofing on an affected system.
Recommendation:
Mozilla has released new versions of the product to address the issues and they can be downloaded at the following URLs:
- Firefox 89 for Windows
https://www.mozilla.org/en-US/firefox/all/
- Firefox ESR 78.11 for Windows
https://www.mozilla.org/en-US/firefox/organizations/all/
More Information:
- https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/
- https://www.mozilla.org/en-US/security/advisories/mfsa2021-24/
- https://www.hkcert.org/security-bulletin/mozilla-products-multiple-vulnerabilities_20210602
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29959 (to CVE-2021-29961)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29964
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29966
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29967