CVE-2022-46874Code Injection in Mozilla Firefox

Severity
8.8HIGHNVD
OSV6.5
EPSS
0.4%
top 40.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateFeb 6

Description

A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5mozilla/thunderbirdunspecified102.6.1+1
NVDmozilla/thunderbird< 102.6
Debianmozilla/thunderbird< 1:102.6.0-1~deb11u1+3
Ubuntumozilla/thunderbird< 1:102.7.1+build2-0ubuntu0.18.04.1+2
CVEListV5mozilla/firefoxunspecified108

🔴Vulnerability Details

6
OSV
thunderbird vulnerabilities2023-02-06
OSV
firefox regressions2023-01-05
GHSA
GHSA-pwwf-7f48-895h: A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place2022-12-22
OSV
CVE-2022-46874: A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place2022-12-22
CVEList
CVE-2022-46874: A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place2022-12-22

📋Vendor Advisories

9
Ubuntu
Thunderbird vulnerabilities2023-02-06
Ubuntu
Firefox regressions2023-01-10
Ubuntu
Firefox vulnerabilities2022-12-15
Red Hat
Mozilla: Drag and Dropped Filenames could have been truncated to malicious extensions2022-12-13
Debian
CVE-2022-46874: firefox - A file with a long filename could have had its filename truncated to remove the ...2022
CVE-2022-46874 — Code Injection in Mozilla Firefox | cvebase