Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-46881
HistoryDec 22, 2022 - 12:00 a.m.

CVE-2022-46881

2022-12-2200:00:00
ubuntu.com
ubuntu.com
15
webgl firefox memorycorruption thunderbirdunix exploitablecrash securityvulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.1%

An optimization in WebGL was incorrect in some cases, and could have led to
memory corruption and a potentially exploitable crash. Note: This
advisory was added on December 13th, 2022 after we better understood the
impact of the issue. The fix was included in the original release of
Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR < 102.6,
and Thunderbird < 102.6.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchthunderbird< 1:102.7.1+build2-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchthunderbird< 1:102.7.1+build2-0ubuntu0.20.04.1UNKNOWN
ubuntu22.04noarchthunderbird< 1:102.7.1+build2-0ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchthunderbird< 1:102.7.1+build2-0ubuntu0.22.10.1UNKNOWN
ubuntu23.04noarchthunderbird< 1:102.7.1+build2-0ubuntu1UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.1%