Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-34471

Опубликовано: 22 дек. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

РелизСтатусПримечание
bionic

released

102.0+build2-0ubuntu0.18.04.1
devel

not-affected

code not present
esm-infra/focal

DNE

focal

released

102.0+build2-0ubuntu0.20.04.1
impish

released

102.0+build2-0ubuntu0.21.10.1
jammy

not-affected

code not present
kinetic

not-affected

code not present
lunar

not-affected

code not present
trusty

DNE

upstream

released

102

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

CVSS3: 6.5
debian
около 3 лет назад

When downloading an update for an addon, the downloaded addon update's ...

CVSS3: 6.5
github
около 3 лет назад

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

suse-cvrf
больше 3 лет назад

Security update for MozillaFirefox

suse-cvrf
больше 3 лет назад

Security update for MozillaFirefox

6.5 Medium

CVSS3