PT-2022-5240 · Mozilla+10 · Thunderbird+12

James Lee

·

Published

2022-10-18

·

Updated

2024-12-12

·

CVE-2022-42927

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 106 Firefox ESR versions prior to 102.4 Thunderbird versions prior to 102.4
Description A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via performance.getEntries(). This issue is related to the inclusion of functions from an untrusted controlled area, which could allow a remote attacker to obtain URL entries from different sources by opening a specially crafted malicious site.
Recommendations For Firefox versions prior to 106, update to version 106 or later to resolve the issue. For Firefox ESR versions prior to 102.4, update to version 102.4 or later to resolve the issue. For Thunderbird versions prior to 102.4, update to version 102.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the performance.getEntries() function until a patch is available.

Exploit

Fix

Buffer Overflow

Origin Validation Error

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2022:7070
ALSA-2022:7071
ALSA-2022:7178
ALSA-2022:7190
ALT-PU-2022-2886
ALT-PU-2022-2909
ALT-PU-2022-2910
ALT-PU-2022-3045
ALT-PU-2022-3046
ALT-PU-2022-3047
ALT-PU-2023-1137
ALT-PU-2023-1138
ALT-PU-2023-4335
ALT-PU-2023-4336
ALT-PU-2023-5754
ALT-PU-2024-3614
BDU:2022-06516
BDU:2022-06517
BDU:2022-06518
CESA-2022_7070
CESA-2022_7190
CVE-2022-42927
DLA-3156-1
DLA-3170-1
DSA-5259-1
DSA-5262-1
MGASA-2022-0378
OPENSUSE-SU-2022_3726-1
OPENSUSE-SU-2022_4085-1
OPENSUSE-SU-2024:12425-1
OPENSUSE-SU-2024:12429-1
OPENSUSE-SU-2024:12439-1
OPENSUSE-SU-2024:14572-1
RHSA-2022:7066
RHSA-2022:7068
RHSA-2022:7069
RHSA-2022:7070
RHSA-2022:7071
RHSA-2022:7072
RHSA-2022:7178
RHSA-2022:7181
RHSA-2022:7182
RHSA-2022:7183
RHSA-2022:7184
RHSA-2022:7190
RHSA-2022_7069
RHSA-2022_7070
RHSA-2022_7071
RHSA-2022_7178
RHSA-2022_7184
RHSA-2022_7190
RLSA-2022:7070
RLSA-2022:7190
SUSE-SU-2022:3698-1
SUSE-SU-2022:3719-1
SUSE-SU-2022:3726-1
SUSE-SU-2022:4085-1
SUSE-SU-2022_3698-1
SUSE-SU-2022_3719-1
SUSE-SU-2022_3726-1
SUSE-SU-2022_4085-1
USN-5709-1
USN-5709-2
USN-5724-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu