[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2FIREFOX-2023-008 --- firefox

ID: oval:org.secpod.oval:def:1701781Date: (C)2023-10-26   (M)2023-11-10
Class: PATCHFamily: unix




The Mozilla Foundation Security Advisory describes this flaw as: An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Firefox for Linux. Other operating systems are unaffected.* A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.less thanbr/greater than *Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox less than 108, Thunderbird less than 102.6.1, Thunderbird less than 102.6, and Firefox ESR less than 102.6. The Mozilla Foundation Security Advisory describes this flaw as: Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 107 and Firefox ESR 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. The Mozilla Foundation Security Advisory describes this flaw as: A missing check related to tex units could have led to a use-after-free and potentially exploitable crash. The Mozilla Foundation Security Advisory describes this flaw as: An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. The Mozilla Foundation Security Advisory describes this flaw as: A use-after-free in WebGL extensions could have led to a potentially exploitable crash

Platform:
Amazon Linux 2
Product:
firefox
Reference:
ALAS2FIREFOX-2023-008
CVE-2022-46872
CVE-2022-46874
CVE-2022-46878
CVE-2022-46880
CVE-2022-46881
CVE-2022-46882
CVE    6
CVE-2022-46878
CVE-2022-46882
CVE-2022-46872
CVE-2022-46874
...
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:mozilla:firefox

© SecPod Technologies