Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-46874
HistoryDec 14, 2022 - 12:00 a.m.

CVE-2022-46874

2022-12-1400:00:00
ubuntu.com
ubuntu.com
20
file truncation
user confusion
malicious code
thunderbird
firefox esr
spidermonkey
ubuntu 22.04

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.011

Percentile

84.8%

A file with a long filename could have had its filename truncated to remove
the valid extension, leaving a malicious extension in its place. This could
potentially led to user confusion and the execution of malicious
code.<br />Note: This issue was originally included in the advisories for
Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted,
resulting in it actually being fixed in Thunderbird 102.6.1. This
vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird <
102.6, and Firefox ESR < 102.6.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfirefox< 108.0+build2-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchfirefox< 108.0+build2-0ubuntu0.20.04.1UNKNOWN
ubuntu18.04noarchmozjs38< anyUNKNOWN
ubuntu18.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs68< anyUNKNOWN
ubuntu22.04noarchmozjs78< anyUNKNOWN
ubuntu22.04noarchmozjs91< anyUNKNOWN
ubuntu18.04noarchthunderbird< 1:102.7.1+build2-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchthunderbird< 1:102.7.1+build2-0ubuntu0.20.04.1UNKNOWN
Rows per page:
1-10 of 151

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.011

Percentile

84.8%