CVE-2022-34481: Integer Overflow
In the <code>nsTArrayImpl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Other sources
In the nsTArrayImpl::ReplaceElementsAt() function, an integer overflow could have occurred when the number of elements to replace was too large for the container.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-34481?
CVE-2022-34481 has been classified as a moderate severity vulnerability.
How do I fix CVE-2022-34481?
To fix CVE-2022-34481, update Firefox or Thunderbird to version 102 or Firefox ESR and Thunderbird to version 91.11 or later.
Which software versions are affected by CVE-2022-34481?
CVE-2022-34481 affects Firefox versions prior to 102, Firefox ESR versions prior to 91.11, and Thunderbird versions prior to 102 and 91.11.
What type of vulnerability is CVE-2022-34481?
CVE-2022-34481 is an integer overflow vulnerability that can occur in the nsTArray_Impl::ReplaceElementsAt() function.
Who is the vendor for CVE-2022-34481?
The vendor for CVE-2022-34481 is Mozilla.