CVE-2022-46874
Description
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 102.6.0esr-1 |
| sid | Fixed | 108.0-1 |
| forky | Fixed | 102.6.0esr-1 |
| bullseye | Fixed | 102.6.0esr-1~deb11u1 |
| bookworm | Fixed | 102.6.0esr-1 |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | โ |
| 8 | Fixed | โ |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | โ |
References
- https://access.redhat.com/errata/RHSA-2022:9065
- https://access.redhat.com/errata/RHSA-2022:9080
- https://errata.rockylinux.org/RLSA-2022:9067
- https://security-tracker.debian.org/tracker/CVE-2022-46874
- https://access.redhat.com/errata/RHSA-2022:9067
- https://bugzilla.redhat.com/2153441
- https://bugzilla.redhat.com/2153449
- https://bugzilla.redhat.com/2153454
- https://bugzilla.redhat.com/2153463
- https://bugzilla.redhat.com/2153466
- https://bugzilla.redhat.com/2153467
- https://errata.almalinux.org/8/ALSA-2022-9067.html
- https://errata.almalinux.org/9/ALSA-2022-9065.html
- https://access.redhat.com/errata/RHSA-2022:9074
- https://bugzilla.redhat.com/2149868
- https://errata.almalinux.org/8/ALSA-2022-9074.html
- https://errata.almalinux.org/9/ALSA-2022-9080.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.