Resource management error in Mozilla Firefox - CVE-2022-36315

 

Resource management error in Mozilla Firefox - CVE-2022-36315

Published: July 26, 2022


Vulnerability identifier: #VU65798
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36315
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect implementation of the cache preload. When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata.


Affected software

Mozilla Firefox
Gentoo Linux
Ubuntu
openEuler
firefox (Ubuntu package)
firefox
firefox-debuginfo
firefox-debugsource

How to mitigate CVE-2022-36315

Install updates from vendor's website.

Mozilla Firefox - update to 103.0
firefox (Ubuntu package) - addressed in versions 103.0+build1-0ubuntu0.18.04.1, 103.0+build1-0ubuntu0.20.04.1
firefox - update to 128.8.0-1
firefox-debuginfo - update to 128.8.0-1
firefox-debugsource - update to 128.8.0-1

External References

Related Security Bulletins