[MFSA-2021-37] Security Vulnerabilities fixed in Firefox 91.0.1 and Thunderbird 91.0.1

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1
  • CVE-2021-29991: Header Splitting possible with HTTP/3 Responses (high) Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3.
Package Affected Version
pkg:mozilla/Thunderbird < 91.0.1
pkg:mozilla/Firefox < 91.0.1
Package Fixed Version
pkg:mozilla/Thunderbird = 91.0.1
pkg:mozilla/Firefox = 91.0.1
Source # ID Name URL
Bugzilla 1724896 https://bugzilla.mozilla.org/show_bug.cgi?id=1724896
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 91.0.1
Fixed pkg:mozilla/Thunderbird Thunderbird = 91.0.1
Affected pkg:mozilla/Firefox Firefox < 91.0.1
Fixed pkg:mozilla/Firefox Firefox = 91.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...