First published: Tue Apr 05 2022(Updated: )
By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.8 | 91.8 |
<99 | 99 | |
<91.8 | 91.8 | |
<91.8 | 91.8 | |
Mozilla Firefox | <99.0 | |
Mozilla Firefox ESR | <91.8 | |
Mozilla Thunderbird | <91.8 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-28282 is a vulnerability that allows a use-after-free exploit by destroying an object during JavaScript execution and then referencing the object through a freed pointer, potentially leading to a crash.
CVE-2022-28282 affects Thunderbird < 91.8 and Firefox ESR < 91.8.
CVE-2022-28282 has a severity rating of 6.5, which is classified as medium.
To fix CVE-2022-28282, update your Thunderbird to version 91.8 or higher, or update your Firefox ESR to version 91.8 or higher.
You can find more information about CVE-2022-28282 on the Mozilla Bugzilla and Mozilla security advisories websites.