摘要:
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
安全等级: Low
公告ID: KylinSec-SA-2025-2314
发布日期: 2025年4月20日
关联CVE: CVE-2022-2505
Mozilla开发人员及Mozilla模糊测试团队报告了Firefox 102中存在的内存安全问题。其中部分漏洞已显现出内存损坏迹象,我们推测通过精心构造,攻击者或可利用其中某些漏洞执行任意代码。该漏洞影响以下版本:
Firefox ESR < 102.1
Firefox < 103
Thunderbird < 102.1
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2022-2505 | KY3.4-5A | thunderbird | Unaffected |
CVE-2022-2505 | V6 | thunderbird | Unaffected |