First published: Tue Nov 15 2022(Updated: )
The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.5 | 102.5 |
<107 | 107 | |
<102.5 | 102.5 | |
<102.5 | 102.5 | |
Mozilla Firefox | <107.0 | |
Mozilla Firefox ESR | <102.5 | |
Mozilla Thunderbird | <102.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID of this issue is CVE-2022-45409.
This vulnerability affects Mozilla Thunderbird versions up to and excluding 102.5, Mozilla Firefox versions up to and excluding 107, and Mozilla Firefox ESR versions up to and excluding 102.5.
CVE-2022-45409 has a severity rating of 8.8 (high).
The garbage collector could have been aborted in several states and GCRuntime::finishCollection may not have been called, leading to a use-after-free and potentially exploitable crash.
To fix this vulnerability, update Mozilla Thunderbird to version 102.5 or higher, update Mozilla Firefox to version 107 or higher, or update Mozilla Firefox ESR to version 102.5 or higher.