UBUNTU-CVE-2022-38476
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-38476
UBUNTU-CVE-2022-38476
Summary:
Details: A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
References: https://ubuntu.com/security/CVE-2022-38476, https://www.mozilla.org/en-US/security/advisories/mfsa2022-34/#CVE-2022-38476, https://www.mozilla.org/en-US/security/advisories/mfsa2022-36/#CVE-2022-38476, https://ubuntu.com/security/notices/USN-5663-1, https://www.cve.org/CVERecord?id=CVE-2022-38476
Affected packages
Package
Name: thunderbird
Purl: pkg:deb/ubuntu/thunderbird@1:102.2.2+build1-0ubuntu0.18.04.1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
