First published: Tue Nov 15 2022(Updated: )
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.5 | 102.5 |
Mozilla Firefox | <107.0 | |
Mozilla Firefox ESR | <102.5 | |
Mozilla Thunderbird | <102.5 | |
Apple macOS | ||
Google Android | ||
Linux Linux kernel | ||
Mozilla Firefox ESR | <102.5 | 102.5 |
Mozilla Firefox | <107 | 107 |
All of | ||
Any of | ||
Mozilla Firefox | <107.0 | |
Mozilla Firefox ESR | <102.5 | |
Mozilla Thunderbird | <102.5 | |
Any of | ||
Apple macOS | ||
Google Android | ||
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-45412 is a vulnerability in Thunderbird on Unix-based operating systems that can result in an error message containing uninitialized memory.
CVE-2022-45412 affects Thunderbird on Unix-based operating systems, such as Android, Linux, and MacOS.
CVE-2022-45412 has a severity rating of 8.8 (high).
To fix CVE-2022-45412, update Thunderbird to version 102.5 or higher.
No, Windows systems are not affected by CVE-2022-45412.