CVE-2022-1529
Summary
| CVE | CVE-2022-1529 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2022-12-29 16:41:00 UTC |
| Description | An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Access Denied |
MISC |
bugzilla.mozilla.org |
|
| Security Vulnerabilities fixed in Firefox 100.0.2, Firefox for Android 100.3.0, Firefox ESR 91.9.1, Thunderbird 91.9.1 — Mozilla |
MISC |
www.mozilla.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159855 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-4730)
- 159861 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-4729)
- 159865 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-4776)
- 159866 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-4769)
- 159934 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-4772)
- 159946 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-4765)
- 179304 Debian Security Update for firefox-esr (DSA 5143-1)
- 179311 Debian Security Update for firefox-esr (DLA 3021-1)
- 179351 Debian Security Update for thunderbird (DLA 3041-1)
- 179354 Debian Security Update for thunderbird (DSA 5158-1)
- 184308 Debian Security Update for firefox-esrthunderbird (CVE-2022-1529)
- 198795 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5434-1)
- 198797 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5435-1)
- 240360 Red Hat Update for firefox (RHSA-2022:4729)
- 240361 Red Hat Update for thunderbird (RHSA-2022:4730)
- 240362 Red Hat Update for thunderbird (RHSA-2022:4773)
- 240366 Red Hat Update for thunderbird (RHSA-2022:4774)
- 240367 Red Hat Update for firefox (RHSA-2022:4768)
- 240368 Red Hat Update for thunderbird (RHSA-2022:4772)
- 240369 Red Hat Update for firefox (RHSA-2022:4776)
- 240370 Red Hat Update for firefox (RHSA-2022:4765)
- 240371 Red Hat Update for firefox (RHSA-2022:4766)
- 240372 Red Hat Update for thunderbird (RHSA-2022:4769)
- 353945 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1804
- 376625 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-19)
- 376626 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2022-19)
- 502078 Alpine Linux Security Update for firefox-esr
- 502390 Alpine Linux Security Update for thunderbird
- 502685 Alpine Linux Security Update for firefox
- 710582 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202208-08)
- 710585 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202208-14)
- 752167 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:1818-1)
- 752168 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:1808-1)
- 752170 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:1830-1)
- 753109 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2022:2062-1)
- 940581 AlmaLinux Security Update for thunderbird (ALSA-2022:4769)
- 940585 AlmaLinux Security Update for firefox (ALSA-2022:4776)
- 960150 Rocky Linux Security Update for thunderbird (RLSA-2022:4769)
- 960151 Rocky Linux Security Update for firefox (RLSA-2022:4776)