CVE-2022-34483

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34482. This vulnerability affects Firefox < 102.
References
Link Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1335845 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-24/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1335845 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-24/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

15 Apr 2025, 18:15

Type Values Removed Values Added
CWE CWE-434

21 Nov 2024, 07:09

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1335845 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1335845 - Issue Tracking, Permissions Required, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-24/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-24/ - Vendor Advisory
Summary
  • (es) Un atacante que podría haber convencido a un usuario de arrastrar y soltar una imagen en un sistema de archivos podría haber manipulado el nombre del archivo resultante para que contuviera una extensión ejecutable y, por extensión, potencialmente engañar al usuario para que ejecutara código malicioso. Si bien es muy similar, este es un problema separado de CVE-2022-34482. Esta vulnerabilidad afecta a Firefox &lt; 102.

Information

Published : 2022-12-22 20:15

Updated : 2025-04-15 18:15


NVD link : CVE-2022-34483

Mitre link : CVE-2022-34483

CVE.ORG link : CVE-2022-34483


JSON object : View

Products Affected

mozilla

  • firefox
CWE
NVD-CWE-noinfo CWE-434

Unrestricted Upload of File with Dangerous Type