CERT-In Vulnerability Note
CIVN-2022-0338
Multiple Vulnerabilities in Mozilla Products
Original Issue Date:August 29, 2022
Severity Rating: HIGH
Software Affected
- Mozilla Firefox Thunderbird versions prior to 91.13 & 102.2
- Mozilla Firefox ESR versions prior to 91.13 & 102.2
- Mozilla Firefox versions prior to 104
Overview
Multiple vulnerabilities have been reported in Mozilla products which could allow a remote attacker to bypass security restrictions, execute arbitrary code and cause denial of service attack on the targeted system.
Description
These vulnerabilities exist in Mozilla Firefox due to abuse of XSLT error handling, cross-origin iframe referencing an XSLT document, data race in the PK11_ChangePW function that results in a use-after-free error and memory safety bugs within the browser engine. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restrictions, execute arbitrary code and cause denial of service attack on the targeted system.
Solution
- Upgrade to Mozilla Firefox Thunderbird versions 91.13 and 102.2, Firefox ESR versions 91.13 and 102.2, and Mozilla Firefox version 104
Vendor Information
Mozilla
https://www.mozilla.org/en-US/security/advisories/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-34/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-35/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-36/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-37/
CVE Name
CVE-2022-38472
CVE-2022-38473
CVE-2022-38474
CVE-2022-38475
CVE-2022-38477
CVE-2022-38478
CVE-2022-38476
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|