CVE-2022-46874

A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

15 Apr 2025, 14:15

Type Values Removed Values Added
CWE CWE-94

21 Nov 2024, 07:31

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1746139 - Issue Tracking, Permissions Required () https://bugzilla.mozilla.org/show_bug.cgi?id=1746139 - Issue Tracking, Permissions Required
References () https://security.gentoo.org/glsa/202305-06 - () https://security.gentoo.org/glsa/202305-06 -
References () https://security.gentoo.org/glsa/202305-13 - () https://security.gentoo.org/glsa/202305-13 -
References () https://www.mozilla.org/security/advisories/mfsa2022-51/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-51/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-52/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-52/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-53/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-53/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-54/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-54/ - Vendor Advisory
Summary
  • (es) Se podría haber truncado el nombre de un archivo con un nombre largo para eliminar la extensión válida, dejando una extensión maliciosa en su lugar. Esto podría llevar potencialmente a confusión del usuario y a la ejecución de código malicioso.<br>*Nota*: Este problema se incluyó originalmente en los avisos para Thunderbird 102.6, pero se omitió un parche (específico para Thunderbird), lo que resultó en que en realidad se eliminara. corregido en Thunderbird 102.6.1. Esta vulnerabilidad afecta a Firefox &lt; 108, Thunderbird &lt; 102.6.1, Thunderbird &lt; 102.6 y Firefox ESR &lt; 102.6.

Information

Published : 2022-12-22 20:15

Updated : 2025-04-15 14:15


NVD link : CVE-2022-46874

Mitre link : CVE-2022-46874

CVE.ORG link : CVE-2022-46874


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')