An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2022-52/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2022-53/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2022-51/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1799156 | vendor advisory issue tracking permissions required |
https://security.gentoo.org/glsa/202305-06 | vendor advisory |
https://security.gentoo.org/glsa/202305-13 | vendor advisory |