First published: Tue Sep 20 2022(Updated: )
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.3 | 102.3 |
<102.3 | 102.3 | |
Mozilla Thunderbird | <102.3 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-3155 is a vulnerability in macOS Thunderbird where the com.apple.quarantine attribute is not set on email attachments, allowing applications to be opened immediately without user confirmation.
CVE-2022-3155 affects Thunderbird on macOS by not setting the com.apple.quarantine attribute on received files, allowing applications to be started immediately without user confirmation.
CVE-2022-3155 has a severity rating of 7.8 (high).
To fix CVE-2022-3155 on Thunderbird, update to version 102.3 or later.
You can find more information about CVE-2022-3155 on the Mozilla website and the bugzilla.mozilla.org website.