First published: Tue Apr 05 2022(Updated: )
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.8 | 91.8 |
<99 | 99 | |
<91.8 | 91.8 | |
<91.8 | 91.8 | |
Mozilla Firefox | <99.0 | |
Mozilla Firefox ESR | <91.8 | |
Mozilla Thunderbird | <91.8 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-28281 is a vulnerability that can lead to memory corruption and a potentially exploitable crash in Mozilla Firefox, Firefox ESR, and Thunderbird.
The severity of CVE-2022-28281 is high, with a severity value of 7.
CVE-2022-28281 occurs when a compromised content process sends an unexpected number of WebAuthN Extensions in a Register command to the parent process.
CVE-2022-28281 affects Mozilla Firefox ESR versions up to but excluding 91.8, Mozilla Firefox versions up to but excluding 99, and Mozilla Thunderbird versions up to but excluding 91.8.
To fix CVE-2022-28281, update your Mozilla Firefox, Firefox ESR, or Thunderbird to the latest version available from Mozilla.