First published: Tue Jun 28 2022(Updated: )
The Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101 and Firefox ESR 91.10. Some of these bugs showed evidence of JavaScript prototype or memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.11 | 91.11 |
<102 | 102 | |
<91.11 | 91.11 | |
<102 | 102 | |
<91.11 | 91.11 | |
Mozilla Firefox | <102.0 | |
Mozilla Firefox ESR | <91.11 | |
Mozilla Thunderbird | <91.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-34484 is high.
CVE-2022-34484 can be exploited to run arbitrary code.
Versions 101 and 91.10 of Firefox and Firefox ESR are affected by CVE-2022-34484.
The recommended remedy for CVE-2022-34484 is to update to version 91.11 for Firefox ESR and Thunderbird, and version 102 for Thunderbird and Firefox.
You can find more information about CVE-2022-34484 in the following references: [Bugzilla - Bug 1763634](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1763634%2C1772651), [Mozilla Security Advisories - MFSA2022-26](https://www.mozilla.org/en-US/security/advisories/mfsa2022-26/), [Mozilla Security Advisories - MFSA2022-24](https://www.mozilla.org/en-US/security/advisories/mfsa2022-24/)