PT-2022-2265 · Mozilla+10 · Thunderbird+11

Bo13Oy

·

Published

2021-09-07

·

Updated

2023-09-22

·

CVE-2022-1196

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 91.8 Firefox ESR versions prior to 91.8
Description The issue is related to a use-after-free error that occurs after a VR Process is destroyed, potentially leading to a crash. This error can be exploited by a remote attacker to execute arbitrary code. The vulnerability is associated with a memory release error when handling HTML content after the VR process is destroyed. An attacker can create a specially crafted web page, trick the victim into opening it, and cause a use-after-free error, allowing the execution of arbitrary code in the system.
Recommendations For Thunderbird versions prior to 91.8, update to version 91.8 or later to resolve the issue. For Firefox ESR versions prior to 91.8, update to version 91.8 or later to resolve the issue.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1287
ALSA-2022:1301
ALT-PU-2021-2739
ALT-PU-2021-2849
ALT-PU-2021-3368
ALT-PU-2022-1782
ALT-PU-2022-1809
ALT-PU-2022-1847
ALT-PU-2022-1855
ALT-PU-2022-1941
ALT-PU-2022-1951
ALT-PU-2022-1983
ALT-PU-2022-2044
ALT-PU-2022-2053
BDU:2022-02374
CESA-2022_1287
CESA-2022_1301
CVE-2022-1196
DLA-2971-1
DLA-2978-1
DSA-5113-1
DSA-5118-1
MGASA-2022-0156
MGASA-2022-0157
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2022:1127-1
OPENSUSE-SU-2022_1127-1
OPENSUSE-SU-2022_1176-1
RHSA-2022:1283
RHSA-2022:1284
RHSA-2022:1285
RHSA-2022:1286
RHSA-2022:1287
RHSA-2022:1301
RHSA-2022:1302
RHSA-2022:1303
RHSA-2022:1305
RHSA-2022:1326
RHSA-2022_1284
RHSA-2022_1287
RHSA-2022_1301
RHSA-2022_1302
RLSA-2022:1287
RLSA-2022:1301
SUSE-RU-2022:1114-1
SUSE-RU-2022:1125-1
SUSE-RU-2022:14935-1
SUSE-SU-2022:1127-1
SUSE-SU-2022:1176-1
USN-5393-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu