CVE-2022-3155
published 2022-12-22CVE-2022-3155: When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an…
PriorityP431high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.21%
11.9th percentile
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | — | — |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 102.3 | 102.3 |
| mozilla | thunderbird | >= unspecified < 102.3 | 102.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Attachment files saved to disk on macOS could be executed without warning
vendor_redhat·2022-09-20·CVSS 7.8
CVE-2022-3155 [HIGH] CWE-449 Mozilla: Attachment files saved to disk on macOS could be executed without warning
Mozilla: Attachment files saved to disk on macOS could be executed without warning
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue that Thunderbird did not set the attribute com.apple.quarantine on the received file when saving or opening an email attachment on macOS. If the received file was an application and the user attempted to open it, the application was started immediately without asking the user to confirm.
P
Debian
CVE-2022-3155: thunderbird - When saving or opening an email attachment on macOS, Thunderbird did not set att...
vendor_debian·2022·CVSS 7.8
CVE-2022-3155 [HIGH] CVE-2022-3155: thunderbird - When saving or opening an email attachment on macOS, Thunderbird did not set att...
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Mozilla
Mozilla Foundation Security Advisory 2022-42: CVE-2022-3155
vendor_mozilla·CVSS 7.8
CVE-2022-3155 [HIGH] Mozilla Foundation Security Advisory 2022-42: CVE-2022-3155
Mozilla Foundation Security Advisory 2022-42
CVE: CVE-2022-3155
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.3
GHSA
GHSA-6gfq-p2cr-3q5j: When saving or opening an email attachment on macOS, Thunderbird did not set attribute com
ghsa_unreviewed·2022-12-22
CVE-2022-3155 [HIGH] CWE-276 GHSA-6gfq-p2cr-3q5j: When saving or opening an email attachment on macOS, Thunderbird did not set attribute com
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-22
Published