Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2022-26386

Published: 9 March 2022

Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users. This behavior was reverted to the original, user-specific directory. <br>*This bug only affects Firefox for macOS and Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.7 and Thunderbird < 91.7.

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
firefox-esr
Launchpad, Ubuntu, Debian
trusty Ignored
(out of standard support)
upstream
Released (91.7.0esr-1)
xenial Ignored
(out of standard support)
thunderbird
Launchpad, Ubuntu, Debian
bionic
Released (1:91.7.0+build2-0ubuntu0.18.04.1)
focal
Released (1:91.7.0+build2-0ubuntu0.20.04.1)
impish
Released (1:91.7.0+build2-0ubuntu0.21.10.1)
jammy
Released (1:91.7.0+build2-0ubuntu1)
kinetic
Released (1:91.7.0+build2-0ubuntu1)
trusty Does not exist

upstream
Released (91.7)
xenial Needed