Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ openSUSE-SU-2021:3451-1 — mozillafirefox (CVE-2021-38496 +19 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

This update contains the Firefox Extended Support Release 91.2.0 ESR.

Release 91.2.0 ESR:

  • Fixed: Various stability, functionality, and security fixes

MFSA 2021-45 (bsc#1191332):

  • CVE-2021-38496: Use-after-free in MessageTask
  • CVE-2021-38497: Validation message could have been overlaid on another origin
  • CVE-2021-38498: Use-after-free of nsLanguageAtomService object
  • CVE-2021-32810: Fixed Data race in crossbeam-deque
  • CVE-2021-38500: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2
  • CVE-2021-38501: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2
  • Fixed crash in FIPS mode (bsc#1190710)

Release 91.1.0 ESR:

  • Fixed: Various stability, functionality, and security fixes

MFSA 2021-40 (bsc#1190269, bsc#1190274):

  • CVE-2021-38492: Navigating to mk: URL scheme could load Internet Explorer
  • CVE-2021-38495: Memory safety bugs fixed in Firefox 92 and Firefox ESR 91.1

Release 91.0.1esr ESR:

  • Fixed: Fixed an issue causing buttons on the tab bar to be

resized when loading certain websites (bug 1704404)

  • Fixed: Fixed an issue which caused tabs from private windows

to be visible in non-private windows when viewing switch-to-

tab results in the address bar panel (bug 1720369)

  • Fixed: Various stability fixes
  • Fixed: Security fix MFSA 2021-37 (bsc#1189547)
  • CVE-2021-29991 (bmo#1724896)

Header Splitting possible with HTTP/3 Responses

Firefox Extended Support Release 91.0 ESR

  • New: Some of the highlights of the new Extended Support Release are:
  • A number of user interface changes. For more information,

see the Firefox 89 release notes.

  • Firefox now supports logging into Microsoft, work, and

school accounts using Windows single sign-on. Learn more

  • On Windows, updates can now be applied in the background

while Firefox is not running.

  • Firefox for Windows now offers a new page about:third-party

to help identify compatibility issues caused by third-party

applications

  • Version 2 of Firefox's SmartBlock feature further improves

private browsing. Third party Facebook scripts are blocked to

prevent you from being tracked, but are now automatically

loaded 'just in time' if you decide to 'Log in with Facebook'

on any website.

  • Enhanced the privacy of the Firefox Browser's Private

Browsing mode with Total Cookie Protection, which confines

cookies to the site where they were created, preventing

companis from using cookies to track your browsing across

sites. This feature was originally launched in Firefox's ETP

Strict mode.

  • PDF forms now support JavaScript embedded in PDF files.

Some PDF forms use JavaScript for validation and other

interactive features.

  • You'll encounter less website breakage in Private Browsing

and Strict Enhanced Tracking Protection with SmartBlock,

which provides stand-in scripts so that websites load

properly.

  • Improved Print functionality with a cleaner design and

better integration with your computer's printer settings.

  • Firefox now protects you from supercookies, a type of

tracker that can stay hidden in your browser and track you

online, even after you clear cookies. By isolating

supercookies, Firefox prevents them from tracking your web

browsing from one site to the next.

  • Firefox now remembers your preferred location for saved

bookmarks, displays the bookmarks toolbar by default on new

tabs, and gives you easy access to all of your bookmarks via

a toolbar folder.

  • Native support for macOS devices built with Apple Silicon

CPUs brings dramatic performance improvements over the non-

native build that was shipped in Firefox 83: Firefox launches

over 2.5 times faster and web apps are now twice as

responsive (per the SpeedoMeter 2.0 test). If you are on a

new Apple device, follow these steps to upgrade to the latest

Firefox.

  • Pinch zooming will now be supported for our users with

Windows touchscreen devices and touchpads on Mac devices.

Firefox users may now use pinch to zoom on touch-capable

devices to zoom in and out of webpages.

  • We’ve improved functionality and design for a number of

Firefox search features:

  • Selecting a search engine at the bottom of the search

panel now enters search mode for that engine, allowing you to

see suggestions (if available) for your search terms. The old

behavior (immediately performing a search) is available with

a shift-click.

  • When Firefox autocompletes the URL of one of your search

engines, you can now search with that engine directly in the

address bar by selecting the shortcut in the address bar

results.

  • We’ve added buttons at the bottom of the search panel to

allow you to search your bookmarks, open tabs, and history.

  • Firefox supports AcroForm, whic

Affected software

openSUSE-SU-2021:3451-1 is recorded against 2 packages.

  • mozillafirefox (fixed in 91.2.0-8.54.1)
  • mozillafirefox-branding-sle (fixed in 91-9.5.1)

Timeline and source

Published on 16 October 2021 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

lists.opensuse.org (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2021-10-16
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
mozillafirefox 91.2.0-8.54.1
mozillafirefox-branding-sle 91-9.5.1

References

Free Vulnerability Check

Is your site affected by openSUSE-SU-2021:3451-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2021:3451-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.