CVE-2022-3155: High severity thunderbird vulnerability
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-3155?
CVE-2022-3155 is a vulnerability in macOS Thunderbird where the com.apple.quarantine attribute is not set on email attachments, allowing applications to be opened immediately without user confirmation.
How does CVE-2022-3155 affect Thunderbird on macOS?
CVE-2022-3155 affects Thunderbird on macOS by not setting the com.apple.quarantine attribute on received files, allowing applications to be started immediately without user confirmation.
What is the severity of CVE-2022-3155?
CVE-2022-3155 has a severity rating of 7.8 (high).
How can I fix CVE-2022-3155 on Thunderbird?
To fix CVE-2022-3155 on Thunderbird, update to version 102.3 or later.
Where can I find more information about CVE-2022-3155?
You can find more information about CVE-2022-3155 on the Mozilla website and the bugzilla.mozilla.org website.