Vulnerability CVE-2022-34471: Information

Description

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Published: Dec. 22, 2022
Modified: Jan. 4, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus102.0-alt1125.0.2-alt1ALT-PU-2022-2151-1302831Fixed
firefoxp10105.0.1-alt0.p10.1118.0.2-alt0.p10.1ALT-PU-2022-2930-1307737Fixed
firefoxp9105.0.1-alt0.c9.1105.0.1-alt0.c9.1ALT-PU-2023-4339-1319683Fixed
firefoxc10f1105.0.1-alt0.p10.1112.0.2-alt0.p10.1ALT-PU-2022-2930-1307737Fixed
firefoxc9f2105.0.1-alt0.c9.1105.0.1-alt0.c9.1ALT-PU-2023-1139-1309126Fixed
firefox-esrsisyphus102.1.0-alt1115.10.0-alt1ALT-PU-2022-2458-1304700Fixed
firefox-esrp10102.2.0-alt2115.10.0-alt1ALT-PU-2022-2929-1307737Fixed
firefox-esrp9102.6.0-alt0.c9.1102.11.0-alt0.c9.1ALT-PU-2023-4336-1319683Fixed
firefox-esrc10f1102.2.0-alt2115.9.1-alt0.c10.1ALT-PU-2022-2929-1307737Fixed
firefox-esrc9f2102.6.0-alt0.c9.1102.12.0-alt0.c9.1ALT-PU-2023-1138-1309126Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1766047
  • Issue Tracking
  • Permissions Required
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-24/
  • Vendor Advisory
    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      102.0