UBUNTU-CVE-2021-29964

Source
https://ubuntu.com/security/CVE-2021-29964
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-29964.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2021-29964
Upstream
Published
2021-06-24T14:15:00Z
Modified
2025-10-24T04:50:16Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A locally-installed hostile program could send WM_COPYDATA messages that Firefox would process incorrectly, leading to an out-of-bounds read. This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.

References

Affected packages

Ubuntu:18.04:LTS / mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52@52.9.1-0ubuntu0.18.04.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*
52.3.1-0ubuntu3
52.3.1-7fakesync1
52.8.1-0ubuntu0.18.04.1
52.9.1-0ubuntu0.18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "52.9.1-0ubuntu0.18.04.1",
            "binary_name": "libmozjs-52-0"
        },
        {
            "binary_version": "52.9.1-0ubuntu0.18.04.1",
            "binary_name": "libmozjs-52-dev"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-29964.json"

Ubuntu:18.04:LTS / mozjs38

Package

Name
mozjs38
Purl
pkg:deb/ubuntu/mozjs38@38.8.0~repack1-0ubuntu4?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

38.*
38.8.0~repack1-0ubuntu1
38.8.0~repack1-0ubuntu3
38.8.0~repack1-0ubuntu4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "38.8.0~repack1-0ubuntu4",
            "binary_name": "libmozjs-38-0"
        },
        {
            "binary_version": "38.8.0~repack1-0ubuntu4",
            "binary_name": "libmozjs-38-dev"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-29964.json"

Ubuntu:20.04:LTS / mozjs68

Package

Name
mozjs68
Purl
pkg:deb/ubuntu/mozjs68@68.6.0-1ubuntu1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

68.*
68.5.0-1~fakesync
68.5.0-2~fakesync
68.6.0-1
68.6.0-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "68.6.0-1ubuntu1",
            "binary_name": "libmozjs-68-0"
        },
        {
            "binary_version": "68.6.0-1ubuntu1",
            "binary_name": "libmozjs-68-dev"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-29964.json"

Ubuntu:20.04:LTS / mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52@52.9.1-1ubuntu3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*
52.9.1-1build1
52.9.1-1ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "52.9.1-1ubuntu3",
            "binary_name": "libmozjs-52-0"
        },
        {
            "binary_version": "52.9.1-1ubuntu3",
            "binary_name": "libmozjs-52-dev"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-29964.json"

Ubuntu:22.04:LTS / mozjs78

Package

Name
mozjs78
Purl
pkg:deb/ubuntu/mozjs78@78.15.0-4ubuntu1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

78.*
78.13.0-1
78.15.0-2
78.15.0-4ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "78.15.0-4ubuntu1",
            "binary_name": "libmozjs-78-0"
        },
        {
            "binary_version": "78.15.0-4ubuntu1",
            "binary_name": "libmozjs-78-dev"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-29964.json"