Memory Safety Vulnerability in Firefox (CVE-2022-38478) and Fix Recommendations
A memory‑safety vulnerability (CVE‑2022‑38478) affecting Firefox 103, Firefox ESR 102.1 and 91.12 can leak sensitive data and enable arbitrary code execution, and users should upgrade to Firefox 104 or the latest ESR releases to mitigate the issue.
Firefox versions 103, Firefox ESR 102.1 and 91.12 contain a memory‑safety vulnerability (CVE‑2022‑38478) that may expose sensitive information and allow attackers to execute arbitrary code.
Vulnerability details
Vulnerability Name
GitLab Remote Code Execution Vulnerability
Vulnerability Type
Improper restriction of operations within memory buffer boundaries
Discovery Date
2022/8/25
Scope of Impact
Broad
MPS ID
MPS-2022-54155
CVE ID
CVE-2022-38478
CNVD ID
-
Impact range
Firefox@[103, 104)
Firefox ESR@[102.1, 102.2)
Firefox ESR@[91.12, 91.13)
Remediation
Upgrade Firefox to version 104 or later, upgrade Firefox ESR to 102.2, 91.13, or any newer release.
Laravel Tech Community
Specializing in Laravel development, we continuously publish fresh content and grow alongside the elegant, stable Laravel framework.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.