Loading HuntDB...

GHSA-v22c-c5cc-5mv4

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Related CVEs

Key Information

GHSA ID
GHSA-v22c-c5cc-5mv4
Published
May 14, 2022 3:08 AM
Last Modified
October 21, 2024 3:32 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.