First published: Tue Dec 13 2022(Updated: )
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
<108 | 108 | |
Mozilla Firefox | <108.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Mozilla Firefox ESR | <102.7 | 102.7 |
<102.7 | 102.7 | |
<102.7 | 102.7 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | <=91.12.0esr-1~deb10u1 | 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 |
debian/libusrsctp | <=0.9.3.0+20190127-2<=0.9.3.0+20190127-2+deb10u1 | 0.9.3.0+20201102-2 0.9.5.0-2 |
debian/thunderbird | <=1:91.12.0-1~deb10u1 | 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-46871 is a vulnerability in an out-of-date library (libusrsctp) that could potentially be exploited.
Firefox < 108, Firefox ESR < 102.7, Debian Linux 10.0, Debian Linux 11.0, Thunderbird < 102.7.
CVE-2022-46871 has a severity rating of 8.8 (High).
Update Firefox to version 108 or later, Firefox ESR to version 102.7 or later, Debian Linux to version 10.0 or later, Thunderbird to version 102.7 or later.
You can find more information about CVE-2022-46871 in the references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1795697), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2023-02/), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2023/01/msg00015.html).