CERT-In Vulnerability Note
CIVN-2022-0311
Multiple Vulnerabilities in Mozilla Firefox
Original Issue Date:July 29, 2022
Severity Rating: HIGH
Software Affected
- Mozilla Firefox versions prior to 103
- Mozilla Firefox ESR versions prior to 102.1
- Mozilla Firefox ESR versions prior to 91.12
Overview
Multiple vulnerabilities have been reported in Mozilla Firefox which could allow a remote attacker to bypass security restrictions, access sensitive information, perform spoofing attack, execute arbitrary code and cause a denial of service on the targeted system.
Description
These vulnerabilities exist in Mozilla Firefox due to Memory safety bugs within the browser engine, Unexpected network load while opening local <code>.lnk </code> files, Preload Cache Bypasses Subresource Integrity, Leak of cross-site resource redirecting information while using the Performance API, Hanging of user interface while visiting a website with an overly long URL, Mouse Position spoofing with CSS transforms, Directory indexes for bundled resources reflected URL parameters. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow the attacker to bypass security restrictions, access sensitive information, perform spoofing attack, execute arbitrary code and cause a denial of service on the targeted system.
Solution
Upgrade to Mozilla Firefox version 103, Mozilla Firefox ESR version 102.1 and 91.12
Vendor Information
Mozilla
https://www.mozilla.org/en-US/security/advisories/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-28/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-29/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-30/
CVE Name
CVE-2020-2505
CVE-2022-36314
CVE-2022-36315
CVE-2022-36316
CVE-2022-36317
CVE-2022-36318
CVE-2022-36319
CVE-2022-36320
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|