Description
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3241-1 | firefox-esr security update |
Debian DLA |
DLA-3242-1 | thunderbird security update |
Debian DSA |
DSA-5301-1 | firefox-esr security update |
Debian DSA |
DSA-5303-1 | thunderbird security update |
EUVD |
EUVD-2022-49654 | A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6. |
Ubuntu USN |
USN-5782-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-5824-1 | Thunderbird vulnerabilities |
References
History
Tue, 15 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-04-15T14:03:45.497Z
Reserved: 2022-12-09T00:00:00.000Z
Link: CVE-2022-46874
No data.
Status : Modified
Published: 2022-12-22T20:15:46.257
Modified: 2025-04-15T14:15:37.623
Link: CVE-2022-46874
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN