CVE-2022-46871Use of Unmaintained Third Party Components in Mozilla Firefox

Severity
8.8HIGHNVD
OSV6.5
EPSS
0.9%
top 23.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateFeb 6

Description

An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages10 packages

debiandebian/firefox< firefox 108.0-1 (sid)
CVEListV5mozilla/firefoxunspecified108
NVDmozilla/firefox< 108.0
debiandebian/libusrsctp< firefox 108.0-1 (sid)
debiandebian/firefox-esr< firefox 108.0-1 (sid)

Also affects: Debian Linux 10.0, 11.0

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2023-02-06
OSV
firefox regressions2023-01-05
GHSA
GHSA-5h75-x63q-jgxv: An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited2022-12-22
OSV
CVE-2022-46871: An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited2022-12-22
OSV
firefox vulnerabilities2022-12-15

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2023-02-06
Red Hat
Mozilla: libusrsctp library out of date2023-01-17
Ubuntu
Firefox regressions2023-01-10
Ubuntu
Firefox vulnerabilities2022-12-15
Debian
CVE-2022-46871: firefox - An out of date library (libusrsctp) contained vulnerabilities that could potenti...2022
CVE-2022-46871 — Mozilla Firefox vulnerability | cvebase