Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2022-46875

 

Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2022-46875

Published: December 13, 2022 / Updated: January 16, 2023


Vulnerability identifier: #VU70148
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46875
CWE-ID: CWE-357
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to executable file warning is not displayed when downloading .atloc and .ftploc files. A remote attacker can trick the victim into downloading and executing dangerous files.

Note, the vulnerability affects macOS installations only.


Affected software

Mozilla Firefox
Firefox ESR
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
Oracle Solaris
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Workstation Extension
openSUSE Leap
SUSE Linux Enterprise Module for Packagehub Subpackages
mozilla-thunderbird
mozilla-firefox
MozillaFirefox
MozillaFirefox-debuginfo
MozillaFirefox-debugsource
MozillaFirefox-devel
MozillaFirefox-translations-common
MozillaFirefox-translations-other
MozillaThunderbird-translations-other
MozillaThunderbird-translations-common
MozillaThunderbird-debugsource
MozillaThunderbird-debuginfo
MozillaThunderbird
MozillaFirefox-branding-upstream
mail-client/thunderbird
mail-client/thunderbird-bin
www-client/firefox
Mozilla Thunderbird
Synthetic Playback Agent

How to mitigate CVE-2022-46875

Install updates from vendor's website.

Mozilla Firefox - update to 108.0
Firefox ESR - update to 102.6.0
Mozilla Thunderbird - update to 102.6.0
Synthetic Playback Agent - update to 8.1.4 IF17
mozilla-thunderbird - update to 102.6.0
mozilla-firefox - update to 102.6.0esr
MozillaFirefox - addressed in versions 102.6.0-150000.150.68.1, 102.6.0-150200.152.70.1
MozillaFirefox-debuginfo - addressed in versions 102.6.0-150000.150.68.1, 102.6.0-150200.152.70.1
MozillaFirefox-debugsource - addressed in versions 102.6.0-150000.150.68.1, 102.6.0-150200.152.70.1
MozillaFirefox-devel - addressed in versions 102.6.0-150000.150.68.1, 102.6.0-150200.152.70.1
MozillaFirefox-translations-common - addressed in versions 102.6.0-150000.150.68.1, 102.6.0-150200.152.70.1
MozillaFirefox-translations-other - addressed in versions 102.6.0-150000.150.68.1, 102.6.0-150200.152.70.1
MozillaThunderbird-translations-other - update to 102.6.0-150200.8.96.1
MozillaThunderbird-translations-common - update to 102.6.0-150200.8.96.1
MozillaThunderbird-debugsource - update to 102.6.0-150200.8.96.1
MozillaThunderbird-debuginfo - update to 102.6.0-150200.8.96.1
MozillaThunderbird - update to 102.6.0-150200.8.96.1
MozillaFirefox-branding-upstream - update to 102.6.0-150200.152.70.1
mail-client/thunderbird - update to 102.7.0
mail-client/thunderbird-bin - update to 102.7.0
www-client/firefox - update to 104

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins