CVE-2021-29972 PUBLISHED

A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. This vulnerability affects Firefox < 90.

EPSS 0.47% · 64.3th percentile

Risk Scores

EPSS Score
0.47%
64.3th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSfirefox88.0+build2-0ubuntu0.20.04.1, *, *
Ubuntu:20.04:LTSmozjs680, 68.5.0-1~fakesync, 68.5.0-2~fakesync
Ubuntu:20.04:LTSmozjs5252.9.1-1ubuntu3, 0, 52.9.1-1build1
Ubuntu:18.04:LTSmozjs5252.3.1-0ubuntu3, 0, 52.3.1-7fakesync1
Ubuntu:22.04:LTSmozjs780, 78.13.0-1, 78.15.0-4ubuntu1
Ubuntu:18.04:LTSfirefox*, *, *
Ubuntu:18.04:LTSmozjs3838.8.0~repack1-0ubuntu4, 38.8.0~repack1-0ubuntu3, 38.8.0~repack1-0ubuntu1

Timeline

References

Open in Interactive Console →