QID 353945
Date Published: 2022-06-09
QID 353945: Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1804
The mozilla foundation security advisory describes this flaw as: an attacker could have sent a message to the parent process where the contents were used to double-index into a javascript object, leading to prototype pollution and ultimately attacker-controlled javascript executing in the privileged parent process. (
( CVE-2022-1529) he mozilla foundation security advisory describes this flaw as: if an attacker was able to corrupt the methods of an array object in javascript via prototype pollution, they could have achieved execution of attacker-controlled javascript code in a privileged context. (
( CVE-2022-1802)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2-2022-1804 -
alas.aws.amazon.com/AL2/ALAS-2022-1804.html
CVEs related to QID 353945
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2022-1804 | Amazon Linux 2 |
|