Use-after-free in Firefox for Android and Mozilla Firefox - CVE-2022-45407

 

Use-after-free in Firefox for Android and Mozilla Firefox - CVE-2022-45407

Published: November 15, 2022


Vulnerability identifier: #VU69323
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45407
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when using FontFace() on a background worker. A remote attacker can trick the victim to visit a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Firefox for Android
Mozilla Firefox
Gentoo Linux
Ubuntu
www-client/firefox
firefox (Ubuntu package)

How to mitigate CVE-2022-45407

Install updates from vendor's website.

Firefox for Android - update to 107.1.0
Mozilla Firefox - update to 107.0
www-client/firefox - update to 104
firefox (Ubuntu package) - addressed in versions 107.0+build2-0ubuntu0.18.04.1, 107.0+build2-0ubuntu0.20.04.1

External References

Related Security Bulletins