CVE-2022-38476
Mozilla: Data race and potential use-after-free in PK11_ChangePW
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
Podría producirse una carrera de datos en la función <code>PK11_ChangePW</code>, lo que podría provocar una vulnerabilidad de use-after-free. En Firefox, este bloqueo protegía los datos cuando un usuario cambiaba su contraseña maestra. Esta vulnerabilidad afecta a Firefox ESR < 102.2 y Thunderbird < 102.2.
The Mozilla Foundation Security Advisory describes this flaw as:
A data race could occur in the PK11_ChangePW function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-19 CVE Reserved
- 2022-08-25 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2022-34 | 2023-01-03 | |
https://www.mozilla.org/security/advisories/mfsa2022-36 | 2023-01-03 | |
https://access.redhat.com/security/cve/CVE-2022-38476 | 2022-08-24 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2120678 | 2022-08-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 102.2 Search vendor "Mozilla" for product "Firefox Esr" and version " < 102.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 102.2 Search vendor "Mozilla" for product "Thunderbird" and version " < 102.2" | - |
Affected
|