CVE-2022-45406

If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1791975 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1791975 - Issue Tracking, Permissions Required, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-48/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-48/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-49/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-49/ - Vendor Advisory
Summary
  • (es) Si se produjo una condición de falta de memoria al crear un JavaScript global, un dominio de JavaScript puede eliminarse mientras las referencias al mismo permanezcan en una BaseShape. Esto podría provocar un use after free que provocaría un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Firefox ESR &lt; 102,5, Thunderbird &lt; 102.5 y Firefox &lt; 107.

Information

Published : 2022-12-22 20:15

Updated : 2025-04-15 15:16


NVD link : CVE-2022-45406

Mitre link : CVE-2022-45406

CVE.ORG link : CVE-2022-45406


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr
CWE
CWE-416

Use After Free