Описание
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | code not present |
esm-infra/focal | DNE | |
focal | released | 117.0+build2-0ubuntu0.20.04.1 |
jammy | not-affected | code not present |
lunar | ignored | end of life, was needs-triage |
mantic | not-affected | code not present |
noble | not-affected | code not present |
trusty | ignored | end of standard support |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | ignored | |
esm-apps/noble | ignored | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | ignored | |
lunar | ignored | end of life, was needs-triage |
mantic | ignored | end of life, was needs-triage |
noble | ignored | |
trusty | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | DNE | |
esm-apps/bionic | ignored | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
lunar | DNE | |
mantic | DNE | |
noble | DNE | |
trusty | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | DNE | |
esm-apps/focal | ignored | |
esm-infra/bionic | ignored | |
focal | ignored | |
jammy | DNE | |
lunar | DNE | |
mantic | DNE | |
noble | DNE | |
trusty | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra/focal | ignored | |
focal | ignored | |
jammy | DNE | |
lunar | DNE | |
mantic | DNE | |
noble | DNE | |
trusty | DNE | |
upstream | ignored |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-apps/jammy | ignored | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | ignored | |
lunar | ignored | end of life, was needs-triage |
mantic | DNE | |
noble | DNE | |
trusty | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | ignored | |
lunar | DNE | |
mantic | DNE | |
noble | DNE | |
trusty | DNE | |
upstream | ignored |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | released | 1:115.2.0+build1-0ubuntu1 |
esm-infra/focal | DNE | |
focal | released | 1:102.15.1+build1-0ubuntu0.20.04.1 |
jammy | released | 1:102.15.1+build1-0ubuntu0.22.04.1 |
lunar | released | 1:102.15.1+build1-0ubuntu0.23.04.1 |
mantic | released | 1:115.2.0+build1-0ubuntu1 |
noble | released | 1:115.2.0+build1-0ubuntu1 |
trusty | ignored | end of standard support |
upstream | needs-triage |
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
When creating a callback over IPC for showing the File Picker window, ...
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, and Thunderbird < 115.2.
Уязвимость функции FilePickerShownCallback браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
EPSS
6.5 Medium
CVSS3