UBUNTU-CVE-2022-45419

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2022-45419
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-45419.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-45419
Related
Published
2022-11-16T00:00:00Z
Modified
2022-11-16T00:00:00Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.

References

Affected packages

Ubuntu:18.04:LTS / firefox

Package

Name
firefox
Purl
pkg:deb/ubuntu/firefox@107.0+build2-0ubuntu0.18.04.1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
107.0+build2-0ubuntu0.18.04.1

Affected versions

56.*

56.0+build6-0ubuntu1

57.*

57.0.1+build2-0ubuntu1

59.*

59.0.1+build1-0ubuntu1
59.0.2+build1-0ubuntu1

60.*

60.0+build2-0ubuntu1
60.0.1+build2-0ubuntu0.18.04.1
60.0.2+build1-0ubuntu0.18.04.1

61.*

61.0+build3-0ubuntu0.18.04.1
61.0.1+build1-0ubuntu0.18.04.1

62.*

62.0+build2-0ubuntu0.18.04.3
62.0+build2-0ubuntu0.18.04.4
62.0+build2-0ubuntu0.18.04.5
62.0.3+build1-0ubuntu0.18.04.1

63.*

63.0+build2-0ubuntu0.18.04.2
63.0.3+build1-0ubuntu0.18.04.1

64.*

64.0+build3-0ubuntu0.18.04.1

65.*

65.0+build2-0ubuntu0.18.04.1
65.0.1+build2-0ubuntu0.18.04.1

66.*

66.0+build3-0ubuntu0.18.04.1
66.0.1+build1-0ubuntu0.18.04.1
66.0.2+build1-0ubuntu0.18.04.1
66.0.3+build1-0ubuntu0.18.04.1
66.0.4+build3-0ubuntu0.18.04.1
66.0.5+build1-0ubuntu0.18.04.1

67.*

67.0+build2-0ubuntu0.18.04.1
67.0.1+build1-0ubuntu0.18.04.1
67.0.2+build2-0ubuntu0.18.04.1
67.0.3+build1-0ubuntu0.18.04.1
67.0.4+build1-0ubuntu0.18.04.1

68.*

68.0+build3-0ubuntu0.18.04.1
68.0.1+build1-0ubuntu0.18.04.1
68.0.2+build1-0ubuntu0.18.04.1

69.*

69.0+build2-0ubuntu0.18.04.1
69.0.1+build1-0ubuntu0.18.04.1
69.0.2+build1-0ubuntu0.18.04.1

70.*

70.0+build2-0ubuntu0.18.04.1
70.0.1+build1-0ubuntu0.18.04.1

71.*

71.0+build5-0ubuntu0.18.04.1

72.*

72.0.1+build1-0ubuntu0.18.04.1
72.0.2+build1-0ubuntu0.18.04.1

73.*

73.0+build3-0ubuntu0.18.04.1
73.0.1+build1-0ubuntu0.18.04.1

74.*

74.0+build3-0ubuntu0.18.04.1
74.0.1+build1-0ubuntu0.18.04.1

75.*

75.0+build3-0ubuntu0.18.04.1

76.*

76.0+build2-0ubuntu0.18.04.1
76.0.1+build1-0ubuntu0.18.04.1

77.*

77.0.1+build1-0ubuntu0.18.04.1

78.*

78.0.1+build1-0ubuntu0.18.04.1
78.0.2+build2-0ubuntu0.18.04.1

79.*

79.0+build1-0ubuntu0.18.04.1

80.*

80.0+build2-0ubuntu0.18.04.1
80.0.1+build1-0ubuntu0.18.04.1

81.*

81.0+build2-0ubuntu0.18.04.1
81.0.2+build1-0ubuntu0.18.04.1

82.*

82.0+build2-0ubuntu0.18.04.1
82.0.2+build1-0ubuntu0.18.04.1
82.0.3+build1-0ubuntu0.18.04.1

83.*

83.0+build2-0ubuntu0.18.04.2

84.*

84.0+build3-0ubuntu0.18.04.1
84.0.1+build1-0ubuntu0.18.04.1
84.0.2+build1-0ubuntu0.18.04.1

85.*

85.0+build1-0ubuntu0.18.04.1
85.0.1+build1-0ubuntu0.18.04.1

86.*

86.0+build3-0ubuntu0.18.04.1
86.0.1+build1-0ubuntu0.18.04.1

87.*

87.0+build3-0ubuntu0.18.04.2

88.*

88.0+build2-0ubuntu0.18.04.2
88.0.1+build1-0ubuntu0.18.04.2

89.*

89.0+build2-0ubuntu0.18.04.2
89.0.1+build1-0ubuntu0.18.04.1
89.0.2+build1-0ubuntu0.18.04.1

90.*

90.0+build1-0ubuntu0.18.04.1
90.0.2+build1-0ubuntu0.18.04.1

91.*

91.0+build2-0ubuntu0.18.04.1
91.0.1+build1-0ubuntu0.18.04.1
91.0.2+build1-0ubuntu0.18.04.1

92.*

92.0+build3-0ubuntu0.18.04.1

93.*

93.0+build1-0ubuntu0.18.04.1

94.*

94.0+build3-0ubuntu0.18.04.1

95.*

95.0+build1-0ubuntu0.18.04.1
95.0.1+build2-0ubuntu0.18.04.1

96.*

96.0+build2-0ubuntu0.18.04.1

97.*

97.0+build2-0ubuntu0.18.04.1
97.0.2+build1-0ubuntu0.18.04.1

98.*

98.0+build3-0ubuntu0.18.04.2
98.0.1+build2-0ubuntu0.18.04.1
98.0.2+build1-0ubuntu0.18.04.1

99.*

99.0+build2-0ubuntu0.18.04.2

100.*

100.0+build2-0ubuntu0.18.04.1
100.0.2+build1-0ubuntu0.18.04.1

101.*

101.0.1+build1-0ubuntu0.18.04.1

102.*

102.0+build2-0ubuntu0.18.04.1

103.*

103.0+build1-0ubuntu0.18.04.1

104.*

104.0+build3-0ubuntu0.18.04.1

105.*

105.0+build2-0ubuntu0.18.04.1

106.*

106.0.2+build1-0ubuntu0.18.04.1
106.0.5+build1-0ubuntu0.18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "firefox-locale-de": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-kn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fy": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-eo": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-km": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-or": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-az": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-lt": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hy": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-kk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sv": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-uk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ca": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-is": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-dbg": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ne": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ga": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-it": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ja": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-lg": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ms": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-dev": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ia": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ko": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mai": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nb": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-mozsymbols": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-vi": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-zh-hans": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-he": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sw": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-el": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-oc": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-xh": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-csb": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-geckodriver": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-cs": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hsb": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-zu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-my": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ro": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ar": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-szl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-af": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nso": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-si": "107.0+build2-0ubuntu0.18.04.1",
            "firefox": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-cy": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fa": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-cak": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sq": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-en": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-tr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-br": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-et": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ast": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-th": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-da": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fi": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ku": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ru": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-bg": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-bn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-kab": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ml": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-an": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-be": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-eu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-pa": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-as": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-id": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-bs": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-te": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-lv": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ka": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ta": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gd": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-zh-hant": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-uz": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hi": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-es": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ur": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-pl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-pt": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sl": "107.0+build2-0ubuntu0.18.04.1"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / mozjs52

Package

Name
mozjs52

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*

52.3.1-0ubuntu3
52.3.1-7fakesync1
52.8.1-0ubuntu0.18.04.1
52.9.1-0ubuntu0.18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / mozjs38

Package

Name
mozjs38

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

38.*

38.8.0~repack1-0ubuntu1
38.8.0~repack1-0ubuntu3
38.8.0~repack1-0ubuntu4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mozjs52

Package

Name
mozjs52

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*

52.9.1-1build1
52.9.1-1ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mozjs68

Package

Name
mozjs68

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

68.*

68.5.0-1~fakesync
68.5.0-2~fakesync
68.6.0-1
68.6.0-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mozjs78

Package

Name
mozjs78

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

78.*

78.13.0-1
78.15.0-2
78.15.0-4ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mozjs91

Package

Name
mozjs91

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

91.*

91.5.1-0ubuntu1
91.6.0-1
91.6.0-2
91.7.0-2
91.10.0-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}