UBUNTU-CVE-2022-22756
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-22756
UBUNTU-CVE-2022-22756
Summary:
Details: If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
References: https://ubuntu.com/security/CVE-2022-22756, https://www.mozilla.org/en-US/security/advisories/mfsa2022-04/#CVE-2022-22756, https://www.mozilla.org/en-US/security/advisories/mfsa2022-05/#CVE-2022-22756, https://ubuntu.com/security/notices/USN-5284-1, https://ubuntu.com/security/notices/USN-5345-1, https://www.cve.org/CVERecord?id=CVE-2022-22756
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build2-0ubuntu0.18.04.1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
