| CERT-In Vulnerability Note 
                                                                      CIVN-2022-0338 Multiple Vulnerabilities in Mozilla Products
 Original Issue Date:August    29, 2022
 Severity Rating: HIGH
 Software Affected  Mozilla Firefox Thunderbird  versions prior to 91.13 & 102.2Mozilla Firefox ESR versions prior to  91.13 & 102.2Mozilla Firefox versions prior to 104
 Overview Multiple vulnerabilities have been reported in Mozilla products which could allow a remote attacker to bypass security restrictions, execute arbitrary code and cause denial of service attack on the targeted system. DescriptionThese vulnerabilities exist in Mozilla Firefox due to abuse of XSLT error handling, cross-origin iframe referencing an XSLT document, data race in the PK11_ChangePW function that results in a use-after-free error and memory safety bugs within the browser engine. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request. 
 Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restrictions, execute arbitrary code and cause denial of service attack on the targeted system.
 
 
 Solution Upgrade to Mozilla Firefox Thunderbird versions 91.13 and 102.2, Firefox ESR versions 91.13 and 102.2, and Mozilla Firefox version 104 
 Vendor Information Mozillahttps://www.mozilla.org/en-US/security/advisories/
 
 References Mozillahttps://www.mozilla.org/en-US/security/advisories/mfsa2022-33/
 https://www.mozilla.org/en-US/security/advisories/mfsa2022-34/
 https://www.mozilla.org/en-US/security/advisories/mfsa2022-35/
 https://www.mozilla.org/en-US/security/advisories/mfsa2022-36/
 https://www.mozilla.org/en-US/security/advisories/mfsa2022-37/
 
 CVE NameDisclaimerCVE-2022-38472
 CVE-2022-38473
 CVE-2022-38474
 CVE-2022-38475
 CVE-2022-38477
 CVE-2022-38478
 CVE-2022-38476
 
 The information provided herein is on "as is" basis, without warranty of any kind.  Contact Information  Email: info@cert-in.org.in  Phone: +91-11-24368572 Postal address  Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology
 Government of India
 Electronics Niketan
 6, CGO Complex, Lodhi Road,
 New Delhi - 110 003
 India
   |