CVE-2022-45412: High severity Mozilla Thunderbird vulnerability
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Other sources
When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing uninitialized memory in the buffer. This bug only affects Firefox on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.
— Mozilla
When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing uninitialized memory in the buffer. This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.
— Mozilla
When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-45412?
CVE-2022-45412 is a vulnerability in Thunderbird on Unix-based operating systems that can result in an error message containing uninitialized memory.
Which systems are affected by CVE-2022-45412?
CVE-2022-45412 affects Thunderbird on Unix-based operating systems, such as Android, Linux, and MacOS.
What is the severity of CVE-2022-45412?
CVE-2022-45412 has a severity rating of 8.8 (high).
How can I fix CVE-2022-45412?
To fix CVE-2022-45412, update Thunderbird to version 102.5 or higher.
Are Windows systems vulnerable to CVE-2022-45412?
No, Windows systems are not affected by CVE-2022-45412.