Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29913

Опубликовано: 03 мая 2022
Источник: redhat
CVSS3: 6.1

Описание

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.

A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this issue of the parent process not properly checking whether the Speech Synthesis feature is enabled when receiving instructions from a child process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2022:172505.05.2022
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2022:173005.05.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsthunderbirdFixedRHSA-2022:172705.05.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportthunderbirdFixedRHSA-2022:172405.05.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportthunderbirdFixedRHSA-2022:172605.05.2022
Red Hat Enterprise Linux 9thunderbirdFixedRHSA-2022:458918.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1173
https://bugzilla.redhat.com/show_bug.cgi?id=2082038Mozilla: Speech Synthesis feature not properly disabled

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.

CVSS3: 6.5
nvd
почти 3 года назад

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.

CVSS3: 6.5
debian
почти 3 года назад

The parent process would not properly check whether the Speech Synthes ...

CVSS3: 6.5
github
почти 3 года назад

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.

CVSS3: 6.1
fstec
больше 3 лет назад

Уязвимость функции SpeechSynthesis почтового клиента Thunderbird, позволяющая нарушителю раскрыть защищаемую информацию

6.1 Medium

CVSS3