If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown in the composer window. These issues could have given an attacker additional capabilities when targetting releases that did not yet have a fix for CVE-2022-3033 which was reported around three months ago. This vulnerability affects Thunderbird < 102.5.1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Dec 19, 2022 | Dec 15, 2022 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Feb 23, 2023 | Dec 22, 2022 |
| Centos_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade thunderbird-debuginfo | Dec 16, 2022 | Dec 15, 2022 |
| Debian | — | Upgrade thunderbird | Dec 19, 2022 | Dec 19, 2022 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 102.5.1 | Dec 1, 2022 | Nov 30, 2022 |
| Oracle_linux | — | Upgrade thunderbird | Dec 16, 2022 | Nov 30, 2022 |
| Redhat_linux | — | No solution existsUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird | Dec 16, 2022 | Dec 15, 2022 |
| Suse | — | Upgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-other | Dec 7, 2022 | Dec 6, 2022 |
| Ubuntu | — | Upgrade thunderbird | Mar 22, 2023 | Dec 22, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub