PT-2022-2259 · Mozilla+10 · Thunderbird+12

Randell Jesup

·

Published

2022-04-05

·

Updated

2024-12-12

·

CVE-2022-1097

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 99 Firefox ESR versions prior to 91.8 Thunderbird versions prior to 91.8
Description The issue is related to the use of NSSToken objects, which were referenced via direct points and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This could allow a remote attacker to execute arbitrary code using a specially crafted web page.
Recommendations For Firefox versions prior to 99, update to version 99 or later. For Firefox ESR versions prior to 91.8, update to version 91.8 or later. For Thunderbird versions prior to 91.8, update to version 91.8 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1287
ALSA-2022:1301
ALT-PU-2022-1642
ALT-PU-2022-1809
ALT-PU-2022-1847
ALT-PU-2022-1855
ALT-PU-2022-1941
ALT-PU-2022-1951
ALT-PU-2022-1983
ALT-PU-2022-2044
ALT-PU-2022-2053
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-02368
CESA-2022_1287
CESA-2022_1301
CVE-2022-1097
DLA-2971-1
DLA-2978-1
DSA-5113-1
DSA-5118-1
MGASA-2022-0156
MGASA-2022-0157
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2022:1127-1
OPENSUSE-SU-2022_1127-1
OPENSUSE-SU-2022_1176-1
OPENSUSE-SU-2024:11975-1
OPENSUSE-SU-2024:14572-1
RHSA-2022:1283
RHSA-2022:1284
RHSA-2022:1285
RHSA-2022:1286
RHSA-2022:1287
RHSA-2022:1301
RHSA-2022:1302
RHSA-2022:1303
RHSA-2022:1305
RHSA-2022:1326
RHSA-2022_1284
RHSA-2022_1287
RHSA-2022_1301
RHSA-2022_1302
RLSA-2022:1287
RLSA-2022:1301
SUSE-RU-2022:1114-1
SUSE-RU-2022:1125-1
SUSE-RU-2022:14935-1
SUSE-SU-2022:1113-1
SUSE-SU-2022:1127-1
SUSE-SU-2022:1149-1
SUSE-SU-2022:1176-1
SUSE-SU-2022:14936-1
SUSE-SU-2022_1113-1
SUSE-SU-2022_1149-1
SUSE-SU-2022_14936-1
USN-5370-1
USN-5393-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu