CVE-2022-3032
Published: 1 September 2022
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Priority
Status
Package | Release | Status |
---|---|---|
thunderbird Launchpad, Ubuntu, Debian |
bionic |
Released
(1:102.2.2+build1-0ubuntu0.18.04.1)
|
focal |
Released
(1:102.2.2+build1-0ubuntu0.20.04.1)
|
|
jammy |
Released
(1:102.2.2+build1-0ubuntu0.22.04.1)
|
|
kinetic |
Ignored
(end of life, was needs-triage)
|
|
lunar |
Not vulnerable
(1:102.3.3+build1-0ubuntu1)
|
|
trusty |
Ignored
(end of standard support)
|
|
upstream |
Released
(91.13.1)
|
|
xenial |
Ignored
(end of standard support)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |