CVE-2022-1097
Summary
| CVE | CVE-2022-1097 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2022-12-29 17:52:00 UTC |
| Description | <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159748 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-1287)
- 159751 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-1284)
- 159752 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-1302)
- 159753 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-1301)
- 179173 Debian Security Update for firefox-esr (DSA 5113-1)
- 179174 Debian Security Update for firefox-esr (DLA 2971-1)
- 179183 Debian Security Update for thunderbird (DSA 5118-1)
- 179185 Debian Security Update for thunderbird (DLA 2978-1)
- 184160 Debian Security Update for firefox-esrthunderbird (CVE-2022-1097)
- 198733 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5370-1)
- 198755 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5393-1)
- 240205 Red Hat Update for firefox (RHSA-2022:1286)
- 240206 Red Hat Update for firefox (RHSA-2022:1285)
- 240207 Red Hat Update for firefox (RHSA-2022:1287)
- 240208 Red Hat Update for firefox (RHSA-2022:1284)
- 240211 Red Hat Update for thunderbird (RHSA-2022:1302)
- 240212 Red Hat Update for thunderbird (RHSA-2022:1305)
- 240214 Red Hat Update for thunderbird (RHSA-2022:1301)
- 240215 Red Hat Update for thunderbird (RHSA-2022:1326)
- 240428 Red Hat Update for firefox (RHSA-2022:1283)
- 296064 Oracle Solaris 11.4 Support Repository Update (SRU) 46.119.2 Missing (CPUAPR2022)
- 353266 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1789
- 376518 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2022-14)
- 376519 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-13)
- 376522 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2022-15)
- 500461 Alpine Linux Security Update for nss
- 502076 Alpine Linux Security Update for firefox-esr
- 502129 Alpine Linux Security Update for nss
- 502320 Alpine Linux Security Update for nss
- 502388 Alpine Linux Security Update for thunderbird
- 502691 Alpine Linux Security Update for firefox
- 710692 Gentoo Linux Mozilla Network Security Service (NSS) Multiple Vulnerabilities (GLSA 202212-05)
- 751969 SUSE Enterprise Linux Security Update for mozilla-nss (SUSE-SU-2022:1113-1)
- 751972 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:1127-1)
- 751973 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2022:1127-1)
- 752020 SUSE Enterprise Linux Security Update for mozilla-nss (SUSE-SU-2022:1149-1)
- 753416 SUSE Enterprise Linux Security Update for mozilla-nss (SUSE-SU-2022:14936-1)
- 753461 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2022:1176-1)
- 940476 AlmaLinux Security Update for firefox (ALSA-2022:1287)
- 940477 AlmaLinux Security Update for thunderbird (ALSA-2022:1301)
- 960590 Rocky Linux Security Update for thunderbird (RLSA-2022:1301)
- 960633 Rocky Linux Security Update for firefox (RLSA-2022:1287)