CERT-In Vulnerability Note
CIVN-2022-0259
Multiple Vulnerabilities in Mozilla Products
Original Issue Date:June 06, 2022
Severity Rating: HIGH
Software Affected
- Mozilla Firefox iOS version prior to 101
- Mozilla Firefox Thunderbird version prior to 91.10
- Mozilla Firefox ESR version prior to 91.10
- Mozilla Firefox version prior to 101
Overview
Multiple vulnerabilities have been reported in Mozilla products which could allow a remote attacker to disclose sensitive information, bypass security restrictions, execute arbitrary code, perform spoofing attacks and cause denial of service (DoS) attack on the targeted system.
Description
These vulnerabilities exist in Mozilla Firefox due to SQL injection in history tab, Cross-Origin resources length leaked, Heap buffer overflow in WebGL, Browser window spoof using full screen mode, Attacker-influenced path traversal when saving downloaded files, Register allocation problem in WASM on arm64,Uninitialized variable leads to invalid memory read, Braille space character caused incorrect sender email to be shown for a digitally signed email, Querying a WebAuthn token with a large number of allow Credential entries may have leaked cross-origin information, HTML Parsing incorrectly ended HTML comments prematurely, CSP bypass enabling stylesheet injection, Incorrect Assertion caused by unoptimized array shift operations, Memory Corruption when manipulating webp images and Memory safety bugs. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to disclose sensitive information, bypass security restrictions, execute arbitrary code and cause denial of service (DoS) attack on the targeted system.
Solution
- Upgrade to Mozilla Firefox iOS 101, Firefox Thunderbird 91.10, Firefox ESR 91.10 and Mozilla Firefox 101
Vendor Information
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-21/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-23/
References
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2022-21/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-23/
CVE Name
CVE-2022-1887
CVE-2022-1834
CVE-2022-1919
CVE-2022-31736
CVE-2022-31737
CVE-2022-31738
CVE-2022-31739
CVE-2022-31740
CVE-2022-31741
CVE-2022-31742
CVE-2022-31743
CVE-2022-31744
CVE-2022-31745
CVE-2022-31747
CVE-2022-31748
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|