If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote URL was performed, regardless of a configuration to block remote content. An image loaded from the POSTER attribute was shown in the composer window. These issues could have given an attacker additional capabilities when targetting releases that did not yet have a fix for CVE-2022-3033 which was reported around three months ago. This vulnerability affects Thunderbird < 102.5.1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Dec 19, 2022 | Dec 15, 2022 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Feb 23, 2023 | Dec 22, 2022 |
| Centos_linux | — | Upgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird | Dec 16, 2022 | Dec 15, 2022 |
| Debian | — | Upgrade thunderbird | Dec 19, 2022 | Dec 19, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 102.5.1Upgrade to the latest version of Mozilla Thunderbird | Dec 1, 2022 | Nov 30, 2022 |
| Oracle_linux | — | Upgrade thunderbird | Dec 16, 2022 | Nov 30, 2022 |
| Redhat_linux | — | Upgrade thunderbirdNo solution existsUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfo | Dec 16, 2022 | Dec 15, 2022 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-common | Dec 7, 2022 | Dec 6, 2022 |
| Ubuntu | — | Upgrade thunderbird | Mar 22, 2023 | Dec 22, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub