Opened 2 years ago

Closed 2 years ago

#16563 closed enhancement (fixed)

firefox-91.9.1 and js-91.9.1

Reported by: Bruce Dubbs Owned by: ken@…
Priority: high Milestone: 11.2
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description


Change History (3)

comment:1 by ken@…, 2 years ago

Owner: changed from blfs-book to ken@…
Priority: normalhigh
Severity: normalcritical
Status: newassigned

An out of band release. https://www.mozilla.org/en-US/security/advisories/mfsa2022-19/

Two critical javascript vulnerabilities also fixed in 100.0.2 and thunderbird 91.9.1.

Mozilla Foundation Security Advisory 2022-19 Security Vulnerabilities fixed in Firefox 100.0.2, Firefox for Android 100.3.0, Firefox ESR 91.9.1, Thunderbird 91.9.1

Announced

May 20, 2022

Impact

critical

Products

Firefox, Firefox ESR, Firefox for Android, Thunderbird

Fixed in

Firefox 100.0.2 Firefox ESR 91.9.1 Firefox for Android 100.3 Thunderbird 91.9.1

#CVE-2022-1802: Prototype pollution in Top-Level Await implementation

Reporter

Manfred Paul via Trend Micro's Zero Day Initiative

Impact

critical

Description

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. References

Bug 1770137

#CVE-2022-1529: Untrusted input used in JavaScript object indexing, leading to prototype pollution

Reporter

Manfred Paul via Trend Micro's Zero Day Initiative

Impact

critical

Description

An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. References

Bug 1770048

comment:2 by ken@…, 2 years ago

(removed comment about javascript and emails / rss - it was meant to be on the thunderbird ticket)

Last edited 2 years ago by ken@… (previous) (diff)

comment:3 by ken@…, 2 years ago

Resolution: fixed
Status: assignedclosed

Fixed in f9579a89d3459d81bdf9357cfb96b02bdc8134f4 11.1-548

SA 11.1-043

Note: See TracTickets for help on using tickets.