CVE-2021-23964 log

Source
Severity High
Remote Yes
Type Arbitrary code execution
Description
A security issue was found in Firefox before version 85.0 and Thunderbird before version 78.7. Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and Mozilla presumes that with enough effort some of these could have been exploited to run arbitrary code.
Group Package Affected Fixed Severity Status Ticket
AVG-1496 thunderbird 78.6.1-1 78.7.0-1 High Fixed
AVG-1492 firefox 84.0.2-1 85.0-1 High Fixed
Date Advisory Group Package Severity Type
06 Feb 2021 ASA-202102-2 AVG-1496 thunderbird High multiple issues
01 Feb 2021 ASA-202102-1 AVG-1492 firefox High multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2021-03/#CVE-2021-23964
https://www.mozilla.org/en-US/security/advisories/mfsa2021-05/#CVE-2021-23964
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1662507%2C1666285%2C1673526%2C1674278%2C1674835%2C1675097%2C1675844%2C1675868%2C1677590%2C1677888%2C1680410%2C1681268%2C1682068%2C1682938%2C1683736%2C1685260%2C1685925