CVE-2022-3032
Publication date 1 September 2022
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| thunderbird | ||
| 22.04 LTS jammy |
Fixed 1:102.2.2+build1-0ubuntu0.22.04.1
|
|
| 20.04 LTS focal |
Fixed 1:102.2.2+build1-0ubuntu0.20.04.1
|
|
| 18.04 LTS bionic |
Fixed 1:102.2.2+build1-0ubuntu0.18.04.1
|
|
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Ignored end of standard support |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.5 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
References
Related Ubuntu Security Notices (USN)
- USN-5663-1
- Thunderbird vulnerabilities
- 7 October 2022