CVE-2022-46875
published 2022-12-22CVE-2022-46875: The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.63%
46.3th percentile
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 108.0 | 108.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 108 | 108 |
| mozilla | firefox_esr | < 102.6 | 102.6 |
| mozilla | firefox_esr | >= unspecified < 102.6 | 102.6 |
| mozilla | thunderbird | < 102.6 | 102.6 |
| mozilla | thunderbird | >= unspecified < 102.6 | 102.6 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Download Protections were bypassed by .atloc and .ftploc files on Mac OS
vendor_redhat·2022-12-13·CVSS 6.5
CVE-2022-46875 [MEDIUM] CWE-357 Mozilla: Download Protections were bypassed by .atloc and .ftploc files on Mac OS
Mozilla: Download Protections were bypassed by .atloc and .ftploc files on Mac OS
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
The Mozilla Foundation Security Advisory describes this flaw as: The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer.
*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Ent
Debian
CVE-2022-46875: firefox - The executable file warning was not presented when downloading .atloc and .ftplo...
vendor_debian·2022·CVSS 6.5
CVE-2022-46875 [MEDIUM] CVE-2022-46875: firefox - The executable file warning was not presented when downloading .atloc and .ftplo...
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2022-52: CVE-2022-46875
vendor_mozilla·CVSS 6.5
CVE-2022-46875 [MEDIUM] Mozilla Foundation Security Advisory 2022-52: CVE-2022-46875
Mozilla Foundation Security Advisory 2022-52
CVE: CVE-2022-46875
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.6
Mozilla
Mozilla Foundation Security Advisory 2022-53: CVE-2022-46875
vendor_mozilla·CVSS 6.5
CVE-2022-46875 [MEDIUM] Mozilla Foundation Security Advisory 2022-53: CVE-2022-46875
Mozilla Foundation Security Advisory 2022-53
CVE: CVE-2022-46875
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.6
Mozilla
Mozilla Foundation Security Advisory 2022-51: CVE-2022-46875
vendor_mozilla·CVSS 6.5
CVE-2022-46875 [MEDIUM] Mozilla Foundation Security Advisory 2022-51: CVE-2022-46875
Mozilla Foundation Security Advisory 2022-51
CVE: CVE-2022-46875
Product: Firefox
Impact: high
Fixed in: Firefox 108
GHSA
GHSA-w54j-3mgp-xm9q: The executable file warning was not presented when downloading
ghsa_unreviewed·2022-12-22
CVE-2022-46875 [MEDIUM] CWE-287 GHSA-w54j-3mgp-xm9q: The executable file warning was not presented when downloading
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1786188https://security.gentoo.org/glsa/202305-06https://security.gentoo.org/glsa/202305-13https://www.mozilla.org/security/advisories/mfsa2022-51/https://www.mozilla.org/security/advisories/mfsa2022-52/https://www.mozilla.org/security/advisories/mfsa2022-53/https://bugzilla.mozilla.org/show_bug.cgi?id=1786188https://security.gentoo.org/glsa/202305-06https://security.gentoo.org/glsa/202305-13https://www.mozilla.org/security/advisories/mfsa2022-51/https://www.mozilla.org/security/advisories/mfsa2022-52/https://www.mozilla.org/security/advisories/mfsa2022-53/
2022-12-22
Published