Out-of-bounds read in Mozilla products - CVE-2022-3266
Published: October 2, 2022
Vulnerability identifier: #VU67788
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3266
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition when decoding H264 video. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger an out-of-bounds read error and execute arbitrary code on the target system.
Affected software
Mozilla Firefox
Firefox ESR
Firefox for Android
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Anolis OS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Workstation Extension
openSUSE Leap
Ubuntu
SUSE Linux Enterprise Module for Packagehub Subpackages
thunderbird
firefox
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
thunderbird (Ubuntu package)
firefox (Ubuntu package)
Firefox ESR
Firefox for Android
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Anolis OS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Workstation Extension
openSUSE Leap
Ubuntu
SUSE Linux Enterprise Module for Packagehub Subpackages
thunderbird
firefox
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
thunderbird (Ubuntu package)
firefox (Ubuntu package)
How to mitigate CVE-2022-3266
Install updates from vendor's website.
Mozilla Firefox - update to 105.0
Firefox for Android - update to 105.1.0
Firefox ESR - update to 102.3.0
thunderbird - update to 102.3.0-3.0.1
firefox - update to 102.3.0-6.0.1
MozillaThunderbird - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debuginfo - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debugsource - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-common - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-other - update to 102.4.0-150200.8.85.1
thunderbird (Ubuntu package) - addressed in versions 1:102.4.2+build2-0ubuntu0.18.04.1, 1:102.4.2+build2-0ubuntu0.20.04.1, 1:102.4.2+build2-0ubuntu0.22.04.1, 1:102.4.2+build2-0ubuntu0.22.10.1
firefox (Ubuntu package) - addressed in versions 105.0+build2-0ubuntu0.18.04.1, 105.0+build2-0ubuntu0.20.04.1
Firefox for Android - update to 105.1.0
Firefox ESR - update to 102.3.0
thunderbird - update to 102.3.0-3.0.1
firefox - update to 102.3.0-6.0.1
MozillaThunderbird - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debuginfo - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debugsource - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-common - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-other - update to 102.4.0-150200.8.85.1
thunderbird (Ubuntu package) - addressed in versions 1:102.4.2+build2-0ubuntu0.18.04.1, 1:102.4.2+build2-0ubuntu0.20.04.1, 1:102.4.2+build2-0ubuntu0.22.04.1, 1:102.4.2+build2-0ubuntu0.22.10.1
firefox (Ubuntu package) - addressed in versions 105.0+build2-0ubuntu0.18.04.1, 105.0+build2-0ubuntu0.20.04.1