ALT-BU-2022-5116-1
Branch c9f2 update bulletin.
Closed vulnerabilities
BDU:2019-01946
Уязвимость реализации протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с использованием криптографических алгоритмов, содержащих дефекты, позволяющая нарушителю осуществить установку и запуск приложений или получить доступ к конфиденциальным данным
BDU:2019-01947
Уязвимость компонента wpa_supplicant протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с неправильной аутентификацией, позволяющая нарушителю оказать воздействие на целостность и конфиденциальность данных, а также вызвать отказ в обслуживании
BDU:2019-01948
Уязвимость компонента EAP Server протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с некорректным использованием привилегий, позволяющая нарушителю оказать воздействие на целостность и конфиденциальность данных или вызвать отказ в обслуживании
BDU:2019-01949
Уязвимость компонента wpa_supplicant протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с некорректным использованием привилегий, позволяющая нарушителю оказать воздействие на целостность и конфиденциальность данных или вызвать отказ в обслуживании
BDU:2019-04775
Уязвимость компонента защищённого доступа Wi-Fi WPA Supplicant, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-00775
Уязвимость функции wpa_supplicant сервера EAP hostapd, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-03318
Уязвимость реализации протокола WPA программы-демона пользовательского пространства hostapd, позволяющая нарушителю получить учетные данные
BDU:2021-05846
Уязвимость реализации SAE функции wpa_supplicant сертификации устройств беспроводной связи WPA, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2021-05847
Уязвимость реализации SAE функции wpa_supplicant сертификации устройств беспроводной связи WPA, связанная с недостатками процедуры аутентификации, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-07363
Уязвимость реализации SAE клиента защищённого доступа Wi-Fi WPA Supplicant, связанная с раскрытием информации через несоответствие, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-07364
Уязвимость реализации EAP-pwd клиента защищённого доступа Wi-Fi WPA Supplicant, связанная с раскрытием информации через несоответствие, позволяющая нарушителю раскрыть защищаемую информацию
Modified: 2024-11-21
CVE-2019-11555
The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.
- [oss-security] 20190426 Re: wpa_supplicant/hostapd: EAP-pwd message reassembly issue with unexpected fragment
- [oss-security] 20190426 Re: wpa_supplicant/hostapd: EAP-pwd message reassembly issue with unexpected fragment
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-ff1b728d09
- FEDORA-2019-ff1b728d09
- FEDORA-2019-d6bc3771a4
- FEDORA-2019-d6bc3771a4
- FEDORA-2019-28d3ca93d2
- FEDORA-2019-28d3ca93d2
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- 20190527 [SECURITY] [DSA 4450-1] wpa security update
- 20190527 [SECURITY] [DSA 4450-1] wpa security update
- FreeBSD-SA-19:03
- FreeBSD-SA-19:03
- GLSA-201908-25
- GLSA-201908-25
- USN-3969-1
- USN-3969-1
- USN-3969-2
- USN-3969-2
- https://w1.fi/security/2019-5/
- https://w1.fi/security/2019-5/
- https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt
- https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt
- DSA-4450
- DSA-4450
- https://www.openwall.com/lists/oss-security/2019/04/18/6
- https://www.openwall.com/lists/oss-security/2019/04/18/6
Modified: 2024-11-21
CVE-2019-13377
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
- FEDORA-2019-97e9040197
- FEDORA-2019-97e9040197
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- https://usn.ubuntu.com/4098-1/
- https://usn.ubuntu.com/4098-1/
- https://w1.fi/cgit/hostap/commit/?id=147bf7b88a9c231322b5b574263071ca6dbb0503
- https://w1.fi/cgit/hostap/commit/?id=147bf7b88a9c231322b5b574263071ca6dbb0503
- https://w1.fi/cgit/hostap/commit/?id=cd803299ca485eb857e37c88f973fccfbb8600e5
- https://w1.fi/cgit/hostap/commit/?id=cd803299ca485eb857e37c88f973fccfbb8600e5
- DSA-4538
- DSA-4538
Modified: 2024-11-21
CVE-2019-16275
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- FEDORA-2019-0e0b28001d
- FEDORA-2019-0e0b28001d
- FEDORA-2019-65509aac53
- FEDORA-2019-65509aac53
- FEDORA-2019-740834c559
- FEDORA-2019-740834c559
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2265b5ae86
- FEDORA-2019-2265b5ae86
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- USN-4136-1
- USN-4136-1
- USN-4136-2
- USN-4136-2
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- DSA-4538
- DSA-4538
- https://www.openwall.com/lists/oss-security/2019/09/11/7
- https://www.openwall.com/lists/oss-security/2019/09/11/7
Modified: 2024-11-21
CVE-2019-9494
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-1/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-1/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9495
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-2/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-2/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9496
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-3/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-3/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9497
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-4/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9498
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-4/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
Modified: 2024-11-21
CVE-2019-9499
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-4/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
Modified: 2024-11-21
CVE-2022-23303
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
Modified: 2024-11-21
CVE-2022-23304
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
Closed bugs
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-22617
Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
Package thunderbird updated to version 91.9.1-alt0.c9.1 for branch c9f2 in task 300972.
Closed vulnerabilities
BDU:2022-02138
Уязвимость почтового клиента Thunderbird, браузеров Mozilla Firefox и Firefox ESR, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2022-02370
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибкой освобождения памяти при обработке ссылок rel="localization", позволяющая нарушителю выполнить произвольный код
BDU:2022-02373
Уязвимость реализации проверки регулярных выражений (regex для Rust) веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-02941
Уязвимость функции SpeechSynthesis почтового клиента Thunderbird, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-02977
Уязвимость почтового клиента Mozilla Thunderbird, связанная с некорректной обработкой вводимых пользователем данных при обработке подписанных и зашифрованных вложенных сообщений, позволяющая нарушителю проводить спуфинг-атаки
BDU:2022-02988
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2022-03073
Уязвимость уведомлений пользовательского интерфейса поноэкранного режима (Fullscreen UI) веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю проводить спуфинг-атаки
BDU:2022-03074
Уязвимость режима чтения веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю обойти введенные ограничения безопасности
BDU:2022-03075
Уязвимость изолированной среды iframe веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю обойти существующие ограничения безопасности
BDU:2022-03076
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить доступ к защищаемой информации или оказать другое воздействие
BDU:2022-03077
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти существующие ограничения безопасности
BDU:2022-04617
Уязвимость почтового клиента Thunderbird, связанная с ошибками при обновлении цифровой подписи OpenPGP, позволяющая нарушителю выполнить спуфинговую атаку
Modified: 2024-11-21
CVE-2022-1097
NSSToken
objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1745667
- https://bugzilla.mozilla.org/show_bug.cgi?id=1745667
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
Modified: 2024-11-21
CVE-2022-1196
After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1750679
- https://bugzilla.mozilla.org/show_bug.cgi?id=1750679
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
Modified: 2024-11-21
CVE-2022-1197
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected. This vulnerability affects Thunderbird < 91.8.
Modified: 2024-11-21
CVE-2022-1520
When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message A, the message A might be shown with the security status of message B. This vulnerability affects Thunderbird < 91.9.
Modified: 2024-11-21
CVE-2022-1529
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
Modified: 2024-11-21
CVE-2022-1802
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
Modified: 2024-11-21
CVE-2022-24713
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex crate. Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, it us not recommend to deny known problematic regexes.
- https://github.com/rust-lang/regex/commit/ae70b41d4f46641dbc45c7a4f87954aea356283e
- https://github.com/rust-lang/regex/commit/ae70b41d4f46641dbc45c7a4f87954aea356283e
- https://github.com/rust-lang/regex/security/advisories/GHSA-m5pq-gvj9-9vr8
- https://github.com/rust-lang/regex/security/advisories/GHSA-m5pq-gvj9-9vr8
- https://groups.google.com/g/rustlang-security-announcements/c/NcNNL1Jq7Yw
- https://groups.google.com/g/rustlang-security-announcements/c/NcNNL1Jq7Yw
- [debian-lts-announce] 20220407 [SECURITY] [DLA 2971-1] firefox-esr security update
- [debian-lts-announce] 20220407 [SECURITY] [DLA 2971-1] firefox-esr security update
- [debian-lts-announce] 20220411 [SECURITY] [DLA 2978-1] thunderbird security update
- [debian-lts-announce] 20220411 [SECURITY] [DLA 2978-1] thunderbird security update
- FEDORA-2022-8436ac4c39
- FEDORA-2022-8436ac4c39
- FEDORA-2022-d20d44ba98
- FEDORA-2022-d20d44ba98
- FEDORA-2022-ceb3e03c5e
- FEDORA-2022-ceb3e03c5e
- GLSA-202208-08
- GLSA-202208-08
- GLSA-202208-14
- GLSA-202208-14
- DSA-5113
- DSA-5113
- DSA-5118
- DSA-5118
Modified: 2024-11-21
CVE-2022-28281
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1755621
- https://bugzilla.mozilla.org/show_bug.cgi?id=1755621
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
Modified: 2024-11-21
CVE-2022-28282
By using a link with rel="localization"
a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1751609
- https://bugzilla.mozilla.org/show_bug.cgi?id=1751609
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
Modified: 2024-11-21
CVE-2022-28285
When generating the assembly code for MLoadTypedArrayElementHole
, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1756957
- https://bugzilla.mozilla.org/show_bug.cgi?id=1756957
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
Modified: 2024-11-21
CVE-2022-28286
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1735265
- https://bugzilla.mozilla.org/show_bug.cgi?id=1735265
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
Modified: 2024-11-21
CVE-2022-28289
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1663508%2C1744525%2C1753508%2C1757476%2C1757805%2C1758549%2C1758776
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1663508%2C1744525%2C1753508%2C1757476%2C1757805%2C1758549%2C1758776
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-13/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-14/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
- https://www.mozilla.org/security/advisories/mfsa2022-15/
Modified: 2024-11-21
CVE-2022-29909
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1755081
- https://bugzilla.mozilla.org/show_bug.cgi?id=1755081
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
Modified: 2024-11-21
CVE-2022-29911
An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation
could lead to script execution without allow-scripts
being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1761981
- https://bugzilla.mozilla.org/show_bug.cgi?id=1761981
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
Modified: 2024-11-21
CVE-2022-29912
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1692655
- https://bugzilla.mozilla.org/show_bug.cgi?id=1692655
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
Modified: 2024-11-21
CVE-2022-29913
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.
Modified: 2024-11-21
CVE-2022-29914
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1746448
- https://bugzilla.mozilla.org/show_bug.cgi?id=1746448
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
Modified: 2024-11-21
CVE-2022-29916
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1760674
- https://bugzilla.mozilla.org/show_bug.cgi?id=1760674
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
Modified: 2024-11-21
CVE-2022-29917
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1684739%2C1706441%2C1753298%2C1762614%2C1762620%2C1764778
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1684739%2C1706441%2C1753298%2C1762614%2C1762620%2C1764778
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-16/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-17/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
- https://www.mozilla.org/security/advisories/mfsa2022-18/
Closed vulnerabilities
BDU:2022-03770
Уязвимость функции compile_xclass_matchingpath() библиотеки PCRE2, позволяющая нарушителю вызвать отказ в обслуживании или раскрыть защищаемую информацию
BDU:2023-02635
Уязвимость функции pcre2_jit_compile.c библиотеки регулярных выражений PCRE2, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
BDU:2023-02640
Уязвимость функции do_extuni_no_utf компонента pcre2_jit_compile.c библиотеки регулярных выражений PCRE2, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-20454
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.
- https://bugs.exim.org/show_bug.cgi?id=2421
- https://bugs.exim.org/show_bug.cgi?id=2421
- https://bugs.php.net/bug.php?id=78338
- https://bugs.php.net/bug.php?id=78338
- https://bugzilla.redhat.com/show_bug.cgi?id=1735494
- https://bugzilla.redhat.com/show_bug.cgi?id=1735494
- [debian-lts-announce] 20230316 [SECURITY] [DLA 3363-1] pcre2 security update
- [debian-lts-announce] 20230316 [SECURITY] [DLA 3363-1] pcre2 security update
- FEDORA-2020-b11cf352bd
- FEDORA-2020-b11cf352bd
- GLSA-202006-16
- GLSA-202006-16
- https://vcs.pcre.org/pcre2?view=revision&revision=1092
- https://vcs.pcre.org/pcre2?view=revision&revision=1092
Modified: 2025-03-25
CVE-2022-1586
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
- https://bugzilla.redhat.com/show_bug.cgi?id=2077976
- https://bugzilla.redhat.com/show_bug.cgi?id=2077976%2C
- https://bugzilla.redhat.com/show_bug.cgi?id=2077976%2C
- https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a
- https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a%2C
- https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a%2C
- https://github.com/PCRE2Project/pcre2/commit/d4fa336fbcc388f89095b184ba6d99422cfc676c
- https://github.com/PCRE2Project/pcre2/commit/d4fa336fbcc388f89095b184ba6d99422cfc676c
- [debian-lts-announce] 20230316 [SECURITY] [DLA 3363-1] pcre2 security update
- [debian-lts-announce] 20230316 [SECURITY] [DLA 3363-1] pcre2 security update
- FEDORA-2022-9c9691d058
- FEDORA-2022-9c9691d058
- FEDORA-2022-19f4c34184
- FEDORA-2022-19f4c34184
- FEDORA-2022-a3edad0ab6
- FEDORA-2022-a3edad0ab6
- FEDORA-2022-e56085ba31
- FEDORA-2022-e56085ba31
- https://security.netapp.com/advisory/ntap-20221028-0009/
- https://security.netapp.com/advisory/ntap-20221028-0009/
Modified: 2024-11-21
CVE-2022-1587
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
- https://bugzilla.redhat.com/show_bug.cgi?id=2077983%2C
- https://bugzilla.redhat.com/show_bug.cgi?id=2077983%2C
- https://github.com/PCRE2Project/pcre2/commit/03654e751e7f0700693526b67dfcadda6b42c9d0
- https://github.com/PCRE2Project/pcre2/commit/03654e751e7f0700693526b67dfcadda6b42c9d0
- [debian-lts-announce] 20230316 [SECURITY] [DLA 3363-1] pcre2 security update
- [debian-lts-announce] 20230316 [SECURITY] [DLA 3363-1] pcre2 security update
- FEDORA-2022-9c9691d058
- FEDORA-2022-9c9691d058
- FEDORA-2022-19f4c34184
- FEDORA-2022-19f4c34184
- FEDORA-2022-a3edad0ab6
- FEDORA-2022-a3edad0ab6
- FEDORA-2022-e56085ba31
- FEDORA-2022-e56085ba31
- https://security.netapp.com/advisory/ntap-20221028-0009/
- https://security.netapp.com/advisory/ntap-20221028-0009/