跳转到帖子

Red Hat: CVE-2022-46872: CVE-2022-46872 Mozilla: Arbitrary file read from a compromised content process (Multiple Advisories)

recommended_posts

发布于
  • Members

Red Hat: CVE-2022-46872: CVE-2022-46872 Mozilla: Arbitrary file read from a compromised content process (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
12/16/2022
Created
12/16/2022
Added
12/16/2022
Modified
01/28/2025

Description

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

Solution(s)

  • redhat-upgrade-firefox
  • redhat-upgrade-firefox-debuginfo
  • redhat-upgrade-firefox-debugsource
  • redhat-upgrade-thunderbird
  • redhat-upgrade-thunderbird-debuginfo
  • redhat-upgrade-thunderbird-debugsource

References

  • CVE-2022-46872
  • RHSA-2022:9065
  • RHSA-2022:9066
  • RHSA-2022:9067
  • RHSA-2022:9068
  • RHSA-2022:9069
  • RHSA-2022:9072
  • RHSA-2022:9074
  • RHSA-2022:9075
  • RHSA-2022:9078
  • RHSA-2022:9079
  • RHSA-2022:9080
  • RHSA-2022:9081
View more
  • 查看数 693
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…