QID 354078
Date Published: 2022-10-12
QID 354078: Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1855
a flaw was found in mozilla.
The mozilla foundation security advisory describes the issue of mozilla developers and the mozilla fuzzing team reporting memory safety bugs in firefox 102.
Some of these bugs showed evidence of memory corruption, and we presume that with enough effort, some of these could have been exploited to run arbitrary code. (
( CVE-2022-2505) a flaw was found in mozilla.
The mozilla foundation security advisory describes the issue of when visiting directory listings for `chrome://` urls as source text, some parameters were reflected. (
( CVE-2022-36318) a flaw was found in mozilla.
The mozilla foundation security advisory describes the issue of when combining css properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. (
( CVE-2022-36319) a flaw was found in mozilla.
The mozilla foundation security advisory describes the issue of an attacker abusing xslt error handling to associate attacker-controlled content with another origin, which was displayed in the address bar.
This issue could be used to fool the user into submitting data intended for the spoofed origin. (
( CVE-2022-38472) a flaw was found in mozilla.
The mozilla foundation security advisory describes the issue of a cross-origin iframe referencing an xslt document inheriting the parent domains permissions (such as microphone or camera access). (
( CVE-2022-38473) a flaw was found in mozilla.
The mozilla foundation security advisory describes the issue of a data race that could occur in the `pk11_changepw` function, potentially leading to a use-after-free vulnerability.
( CVE-2022-38476) a flaw was found in mozilla.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2-2022-1855 -
alas.aws.amazon.com/AL2/ALAS-2022-1855.html
CVEs related to QID 354078
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2022-1855 | Amazon Linux 2 |
|