Security features bypass in Mozilla Thunderbird - CVE-2022-3155

 

Security features bypass in Mozilla Thunderbird - CVE-2022-3155

Published: September 21, 2022


Vulnerability identifier: #VU67553
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3155
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insecure handling of email attachments in Thunderbird on macOS. The application does not set attribute com.apple.quarantine on the received file, as a result, If the received file is an application and the user attempts to open it, then the application is being executed immediately without asking the user to confirm.


Affected software

Mozilla Thunderbird
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Workstation Extension
openSUSE Leap
SUSE Linux Enterprise Module for Packagehub Subpackages
mail-client/thunderbird
mail-client/thunderbird-bin
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other

How to mitigate CVE-2022-3155

Install updates from vendor's website.

Mozilla Thunderbird - update to 102.3.0
mail-client/thunderbird - update to 102.3.0
mail-client/thunderbird-bin - update to 102.3.0
MozillaThunderbird - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debuginfo - update to 102.4.0-150200.8.85.1
MozillaThunderbird-debugsource - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-common - update to 102.4.0-150200.8.85.1
MozillaThunderbird-translations-other - update to 102.4.0-150200.8.85.1

External References

Related Security Bulletins