CVE-2022-3032
Publication date 1 September 2022
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| thunderbird | ||
| 22.04 LTS jammy |
Fixed 1:102.2.2+build1-0ubuntu0.22.04.1
|
|
| 20.04 LTS focal |
Fixed 1:102.2.2+build1-0ubuntu0.20.04.1
|
|
| 18.04 LTS bionic |
Fixed 1:102.2.2+build1-0ubuntu0.18.04.1
|
|
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Ignored end of standard support |
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | None |
| Availability impact | None |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-5663-1
- Thunderbird vulnerabilities
- 7 October 2022