CVE-2022-36317Mozilla Firefox vulnerability

4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 49.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22

Description

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5mozilla/firefoxunspecified103
NVDmozilla/firefox< 103.0
mozillamozilla/firefox

🔴Vulnerability Details

1
GHSA
GHSA-2459-9w34-v79g: When visiting a website with an overly long URL, the user interface would start to hang2022-12-22

📋Vendor Advisories

2
Debian
CVE-2022-36317: firefox - When visiting a website with an overly long URL, the user interface would start ...2022
Mozilla
Mozilla Foundation Security Advisory 2022-28: CVE-2022-36317