8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
0.002 Low
EPSS
Percentile
52.1%
If a Thunderbird user quoted from an HTML email, for example by replying to
the email, and the email contained either a VIDEO tag with the POSTER
attribute or an OBJECT tag with a DATA attribute, a network request to the
referenced remote URL was performed, regardless of a configuration to block
remote content. An image loaded from the POSTER attribute was shown in the
composer window. These issues could have given an attacker additional
capabilities when targetting releases that did not yet have a fix for
CVE-2022-3033 which was reported around three months ago. This
vulnerability affects Thunderbird < 102.5.1.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | thunderbird | < 1:102.7.1+build2-0ubuntu0.18.04.1 | UNKNOWN |
ubuntu | 20.04 | noarch | thunderbird | < 1:102.7.1+build2-0ubuntu0.20.04.1 | UNKNOWN |
ubuntu | 22.04 | noarch | thunderbird | < 1:102.7.1+build2-0ubuntu0.22.04.1 | UNKNOWN |
ubuntu | 22.10 | noarch | thunderbird | < 1:102.7.1+build2-0ubuntu0.22.10.1 | UNKNOWN |
ubuntu | 23.04 | noarch | thunderbird | < 1:102.7.1+build2-0ubuntu1 | UNKNOWN |