CVE-2022-28282
Summary
| CVE | CVE-2022-28282 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2022-12-30 20:54:00 UTC |
| Description | By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Vulnerabilities fixed in Firefox 99 — Mozilla |
MISC |
www.mozilla.org |
|
| Security Vulnerabilities fixed in Thunderbird 91.8 — Mozilla |
MISC |
www.mozilla.org |
|
| Security Vulnerabilities fixed in Firefox ESR 91.8 — Mozilla |
MISC |
www.mozilla.org |
|
| 1751609 - (CVE-2022-28282) heap-use-after-free in DocumentL10n::TranslateDocument |
MISC |
bugzilla.mozilla.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159748 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-1287)
- 159751 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-1284)
- 159752 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-1302)
- 159753 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-1301)
- 179173 Debian Security Update for firefox-esr (DSA 5113-1)
- 179174 Debian Security Update for firefox-esr (DLA 2971-1)
- 179183 Debian Security Update for thunderbird (DSA 5118-1)
- 179185 Debian Security Update for thunderbird (DLA 2978-1)
- 183728 Debian Security Update for firefox-esrthunderbird (CVE-2022-28282)
- 198733 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5370-1)
- 198755 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5393-1)
- 240205 Red Hat Update for firefox (RHSA-2022:1286)
- 240206 Red Hat Update for firefox (RHSA-2022:1285)
- 240207 Red Hat Update for firefox (RHSA-2022:1287)
- 240208 Red Hat Update for firefox (RHSA-2022:1284)
- 240211 Red Hat Update for thunderbird (RHSA-2022:1302)
- 240212 Red Hat Update for thunderbird (RHSA-2022:1305)
- 240214 Red Hat Update for thunderbird (RHSA-2022:1301)
- 240215 Red Hat Update for thunderbird (RHSA-2022:1326)
- 240428 Red Hat Update for firefox (RHSA-2022:1283)
- 296064 Oracle Solaris 11.4 Support Repository Update (SRU) 46.119.2 Missing (CPUAPR2022)
- 353266 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1789
- 376518 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2022-14)
- 376519 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-13)
- 376522 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2022-15)
- 502076 Alpine Linux Security Update for firefox-esr
- 502388 Alpine Linux Security Update for thunderbird
- 502691 Alpine Linux Security Update for firefox
- 710582 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202208-08)
- 710585 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202208-14)
- 751972 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:1127-1)
- 751973 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2022:1127-1)
- 753461 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2022:1176-1)
- 940476 AlmaLinux Security Update for firefox (ALSA-2022:1287)
- 940477 AlmaLinux Security Update for thunderbird (ALSA-2022:1301)
- 960590 Rocky Linux Security Update for thunderbird (RLSA-2022:1301)
- 960633 Rocky Linux Security Update for firefox (RLSA-2022:1287)