A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105. This vulnerability affects Firefox ESR < 102.6, Firefox < 105, and Thunderbird < 102.6.
References
Link | Resource |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1749292 | Issue Tracking Permissions Required |
https://security.gentoo.org/glsa/202305-06 | |
https://security.gentoo.org/glsa/202305-13 | |
https://www.mozilla.org/security/advisories/mfsa2022-40/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2022-52/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2022-53/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mozilla
Published: 2022-12-22T00:00:00
Updated: 2023-05-03T00:00:00
Reserved: 2022-12-09T00:00:00
Link: CVE-2022-46880
JSON object: View
NVD Information
Status : Modified
Published: 2022-12-22T20:15:47.333
Modified: 2023-05-03T12:16:34.587
Link: CVE-2022-46880
JSON object: View
Redhat Information
No data.
CWE