Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-22747

Опубликовано: 22 дек. 2022
Источник: debian
EPSS Низкий

Описание

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nssfixed2:3.73-1package
firefoxfixed96.0-1package
firefox-esrfixed91.5.0esr-1package
thunderbirdfixed1:91.5.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-01/#CVE-2022-22747

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-02/#CVE-2022-22747

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-03/#CVE-2022-22747

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1735028

  • https://hg.mozilla.org/projects/nss/rev/7ff99e71f3e37faed12bc3cc90a3eed27e3418d0

EPSS

Процентиль: 26%
0.00088
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 4.3
redhat
больше 3 лет назад

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
nvd
больше 2 лет назад

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
github
больше 2 лет назад

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 4.3
fstec
больше 3 лет назад

Уязвимость почтового клиента Thunderbird, браузеров Firefox и Firefox ESR, связанная с неправильной проверкой ввода пустой последовательности pkcs7, передаваемой как часть данных сертификата, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании» (DoS)

EPSS

Процентиль: 26%
0.00088
Низкий