跳转到帖子

Ubuntu: USN-5504-1 (CVE-2022-34471): Firefox vulnerabilities

recommended_posts

发布于
  • Members

Ubuntu: USN-5504-1 (CVE-2022-34471): Firefox vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:C/A:N)
Published
12/22/2022
Created
03/29/2023
Added
03/22/2023
Modified
01/30/2025

Description

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

Solution(s)

  • ubuntu-upgrade-firefox

References

  • https://attackerkb.com/topics/cve-2022-34471
  • CVE - 2022-34471
  • USN-5504-1
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…