First published: Tue Mar 08 2022(Updated: )
Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in /tmp, but this behavior was changed to download them to /tmp where they could be affected by other local users. This behavior was reverted to the original, user-specific directory. This bug only affects Firefox for macOS and Linux. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <0:91.7.0-3.el7_9 | 0:91.7.0-3.el7_9 |
redhat/thunderbird | <0:91.7.0-2.el7_9 | 0:91.7.0-2.el7_9 |
redhat/firefox | <0:91.7.0-3.el8_5 | 0:91.7.0-3.el8_5 |
redhat/thunderbird | <0:91.7.0-2.el8_5 | 0:91.7.0-2.el8_5 |
redhat/firefox | <0:91.7.0-3.el8_1 | 0:91.7.0-3.el8_1 |
redhat/thunderbird | <0:91.7.0-2.el8_1 | 0:91.7.0-2.el8_1 |
redhat/firefox | <0:91.7.0-3.el8_2 | 0:91.7.0-3.el8_2 |
redhat/thunderbird | <0:91.7.0-2.el8_2 | 0:91.7.0-2.el8_2 |
redhat/firefox | <0:91.7.0-3.el8_4 | 0:91.7.0-3.el8_4 |
redhat/thunderbird | <0:91.7.0-2.el8_4 | 0:91.7.0-2.el8_4 |
redhat/firefox | <91.7 | 91.7 |
redhat/thunderbird | <91.7 | 91.7 |
Thunderbird | <91.7 | 91.7 |
Firefox ESR | <91.7 | 91.7 |
Firefox ESR | <91.7 | |
Thunderbird | <91.7 | |
macOS | ||
Linux Kernel | ||
All of | ||
Any of | ||
Firefox ESR | <91.7 | |
Thunderbird | <91.7 | |
Any of | ||
macOS | ||
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The severity of CVE-2022-26386 is classified as moderate.
To fix CVE-2022-26386, upgrade to the latest versions of Firefox or Thunderbird specified in the vulnerability details.
Versions of Firefox before 91.7 are affected by CVE-2022-26386.
Thunderbird versions prior to 91.7 are impacted by CVE-2022-26386.
CVE-2022-26386 impacts Firefox and Thunderbird on macOS and Linux.