PT-2022-2538 · Mozilla+4 · Firefox+4

Gabriele Svelto

+1

·

Published

2022-05-03

·

Updated

2024-12-12

·

CVE-2022-29918

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 100
Description The issue is related to memory safety bugs, including evidence of memory corruption, which could potentially be exploited to run arbitrary code. This can be achieved by a remote attacker using a specially crafted web page, exploiting a buffer overflow in memory. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to 100, update to version 100 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable web pages until the update is applied.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1812
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-02956
CVE-2022-29918
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2024:12044-1
OPENSUSE-SU-2024:14572-1
USN-5411-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu