First published: Tue Dec 13 2022(Updated: )
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could have potentially led to user confusion and the execution of malicious code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <102.6 | 102.6 |
<108 | 108 | |
<102.6 | 102.6 | |
<102.6.1 | 102.6.1 | |
Mozilla Firefox | <108.0 | |
Mozilla Firefox ESR | <102.6 | |
Mozilla Thunderbird | <102.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-46874 is a vulnerability where a file with a long filename could have its filename truncated, potentially leading to user confusion and the execution of malicious code.
CVE-2022-46874 affects Mozilla Thunderbird, Firefox ESR, Firefox, and other related products.
CVE-2022-46874 has a severity rating of 8.8 (high).
CVE-2022-46874 can be exploited by having a file with a long filename, which gets truncated and has a malicious extension added.
Yes, you can find official references for CVE-2022-46874 at the following links: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1746139), [Mozilla Security Advisory - MFS](https://www.mozilla.org/en-US/security/advisories/mfsa2022-54/), [Mozilla Security Advisory - MFS](https://www.mozilla.org/en-US/security/advisories/mfsa2022-52/)