Mozilla FireFox Security Updates 14 December 2022

Mozilla has released security updates to fix vulnerabilities in Firefox 108 and Firefox ESR 102.6.

The addressed vulnerabilities could allow the remote attacker to gain access to sensitive information, perform spoofing attacks, bypass security restrictions, execute arbitrary code and cause a denial of service attack on the affected products.

Successful exploitation of these vulnerabilities may result in a complete compromise of vulnerable systems.

Sample of The Addressed Vulnerabilities:

1- Mozilla Firefox weak security (CVE-2022-46871):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Gain Access

2- Mozilla Firefox safety bugs code execution (CVE-2022-46878):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Gain Access

Vulnerabilities

• CVE-2022-46882

• CVE-2022-46881

• CVE-2022-46880

• CVE-2022-46879

• CVE-2022-46878

• CVE-2022-46877

• CVE-2022-46875

• CVE-2022-46874

• CVE-2022-46873

• CVE-2022-46872

• CVE-2022-46871

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Security Advisory

References