Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2022-3266

Published: 28 September 2022

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

Notes

AuthorNote
mdeslaur
starting with Ubuntu 22.04, the firefox package is just a script
that installs the Firefox snap
Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
bionic
Released (105.0+build2-0ubuntu0.18.04.1)
focal
Released (105.0+build2-0ubuntu0.20.04.1)
jammy Needs triage

kinetic Needs triage

trusty Ignored
(out of standard support)
upstream Needs triage

xenial Needs triage

thunderbird
Launchpad, Ubuntu, Debian
bionic
Released (1:102.4.2+build2-0ubuntu0.18.04.1)
focal
Released (1:102.4.2+build2-0ubuntu0.20.04.1)
jammy
Released (1:102.4.2+build2-0ubuntu0.22.04.1)
kinetic
Released (1:102.4.2+build2-0ubuntu0.22.10.1)
trusty Ignored
(out of standard support)
upstream
Released (102.3)
xenial Needs triage