CVE-2022-46874: Code Injection
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could have potentially led to user confusion and the execution of malicious code.
Other sources
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-46874?
CVE-2022-46874 is a vulnerability where a file with a long filename could have its filename truncated, potentially leading to user confusion and the execution of malicious code.
Which products are affected by CVE-2022-46874?
CVE-2022-46874 affects Mozilla Thunderbird, Firefox ESR, Firefox, and other related products.
What is the severity of CVE-2022-46874?
CVE-2022-46874 has a severity rating of 8.8 (high).
How can CVE-2022-46874 be exploited?
CVE-2022-46874 can be exploited by having a file with a long filename, which gets truncated and has a malicious extension added.
Are there any official references for CVE-2022-46874?
Yes, you can find official references for CVE-2022-46874 at the following links: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1746139), [Mozilla Security Advisory - MFS](https://www.mozilla.org/en-US/security/advisories/mfsa2022-54/), [Mozilla Security Advisory - MFS](https://www.mozilla.org/en-US/security/advisories/mfsa2022-52/)