First published: Tue Apr 05 2022(Updated: )
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 98 and Firefox ESR 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.8 | 91.8 |
<99 | 99 | |
<91.8 | 91.8 | |
<91.8 | 91.8 | |
Mozilla Firefox | <99.0 | |
Mozilla Firefox ESR | <91.8 | |
Mozilla Thunderbird | <91.8 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-28289 is a memory safety bug reported in Thunderbird 91.7 that could lead to memory corruption.
CVE-2022-28289 has a severity rating of 8.8 (high).
CVE-2022-28289 affects Thunderbird 91.7 and Firefox ESR 91.8.
To fix CVE-2022-28289, update Thunderbird to version 91.8 or Firefox ESR to version 91.8.
You can find more information about CVE-2022-28289 on the Mozilla Bugzilla and Mozilla security advisories websites.