First published: Tue Oct 18 2022(Updated: )
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <106 | 106 |
<106 | 106 | |
<102.4 | 102.4 | |
<102.4 | 102.4 | |
Mozilla Firefox | <106.0 | |
Mozilla Firefox ESR | <102.4 | |
Mozilla Thunderbird | <102.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this vulnerability is CVE-2022-42929.
The severity of CVE-2022-42929 is medium with a severity value of 6.5.
The software products affected by CVE-2022-42929 are Mozilla Firefox versions up to 106, Mozilla Firefox ESR versions up to 102.4, and Mozilla Thunderbird versions up to 102.4.
To fix the denial of service issue caused by CVE-2022-42929, users should update their affected software products to the latest version provided by Mozilla.
More information about CVE-2022-42929 can be found at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1789439), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2022-44/)