PT-2022-3940 · Mozilla+9 · Thunderbird+11

Published

2022-07-26

·

Updated

2024-12-12

·

CVE-2022-2505

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 103 Firefox ESR versions prior to 102.1 Thunderbird versions prior to 102.1
Description The issue is caused by memory safety bugs, including evidence of memory corruption, which could potentially be exploited to run arbitrary code. It is also described as a buffer overflow vulnerability in memory, where exploitation could allow a remote attacker to execute arbitrary code using a specially crafted web page.
Recommendations For Firefox versions prior to 103, update to version 103 or later. For Firefox ESR versions prior to 102.1, update to version 102.1 or later. For Thunderbird versions prior to 102.1, update to version 102.1 or later.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:5767
ALSA-2022:5774
ALSA-2022:5777
ALT-PU-2022-2306
ALT-PU-2022-2458
ALT-PU-2022-2515
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2022-2931
ALT-PU-2023-1137
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4335
ALT-PU-2023-4336
ALT-PU-2023-4339
ALT-PU-2023-5754
ALT-PU-2024-3614
BDU:2022-04769
CESA-2022_5773
CESA-2022_5774
CESA-2022_5776
CESA-2022_5777
CVE-2022-2505
OPENSUSE-SU-2022_3281-1
OPENSUSE-SU-2022_3396-1
OPENSUSE-SU-2024:12227-1
OPENSUSE-SU-2024:12228-1
OPENSUSE-SU-2024:14572-1
RHSA-2022:5765
RHSA-2022:5766
RHSA-2022:5767
RHSA-2022:5769
RHSA-2022:5770
RHSA-2022:5771
RHSA-2022:5772
RHSA-2022:5773
RHSA-2022:5774
RHSA-2022:5776
RHSA-2022:5777
RHSA-2022:5778
RHSA-2022_5767
RHSA-2022_5773
RHSA-2022_5774
RHSA-2022_5776
RHSA-2022_5777
RHSA-2022_5778
RLSA-2022:5774
RLSA-2022:5777
SUSE-SU-2022:3272-1
SUSE-SU-2022:3273-1
SUSE-SU-2022:3281-1
SUSE-SU-2022:3396-1
USN-5536-1
USN-5663-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu