Security features bypass in Mozilla Thunderbird - CVE-2022-3155
Published: September 21, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insecure handling of email attachments in Thunderbird on macOS. The application does not set attribute com.apple.quarantine on the received file, as a result, If the received file is an application and the user attempts to open it, then the application is being executed immediately without asking the user to confirm.
Affected software
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Workstation Extension
openSUSE Leap
SUSE Linux Enterprise Module for Packagehub Subpackages
mail-client/thunderbird
mail-client/thunderbird-bin
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
How to mitigate CVE-2022-3155
mail-client/thunderbird - update to 102.3.0
mail-client/thunderbird-bin - update to 102.3.0
MozillaThunderbird - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debuginfo - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debugsource - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-common - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-other - update to 102.4.0-150200.8.85.1