CVE-2022-22747: Medium severity thunderbird vulnerability
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22747.
What is the severity of CVE-2022-22747?
The severity of CVE-2022-22747 is low.
Which software products are affected by CVE-2022-22747?
The software products affected by CVE-2022-22747 are Mozilla Firefox ESR 91.5, Mozilla Thunderbird 91.5, and Mozilla Firefox up to version 96.
What is the remedy for CVE-2022-22747?
The remedy for CVE-2022-22747 is to update Mozilla Firefox ESR to version 91.5, Mozilla Thunderbird to version 91.5, or Mozilla Firefox to version 96.
Is there any additional information about CVE-2022-22747?
Yes, you can find additional information about CVE-2022-22747 in the following references: [Link 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1735028), [Link 2](https://www.mozilla.org/en-US/security/advisories/mfsa2022-03/), [Link 3](https://www.mozilla.org/en-US/security/advisories/mfsa2022-01/)