Описание
A data race could occur in the PK11_ChangePW
function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
kinetic | DNE | |
lunar | DNE | |
trusty | DNE | |
upstream | needs-triage | |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1:102.2.2+build1-0ubuntu0.18.04.1 |
devel | not-affected | 1:102.3.3+build1-0ubuntu1 |
esm-infra/focal | DNE | |
focal | released | 1:102.2.2+build1-0ubuntu0.20.04.1 |
jammy | released | 1:102.2.2+build1-0ubuntu0.22.04.1 |
kinetic | ignored | end of life, was needs-triage |
lunar | not-affected | 1:102.3.3+build1-0ubuntu1 |
trusty | ignored | end of standard support |
upstream | released | 102.2 |
xenial | ignored | end of standard support |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
A data race could occur in the <code>PK11_ChangePW</code> function, po ...
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
Уязвимость функции PK11_ChangePW браузера Mozilla Firefox, почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3