Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2022.5512.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-5512-1)
Summary:The remote host is missing an update for the 'thunderbird' package(s) announced via the USN-5512-1 advisory.
Description:Summary:
The remote host is missing an update for the 'thunderbird' package(s) announced via the USN-5512-1 advisory.

Vulnerability Insight:
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, spoof the UI, bypass CSP restrictions, or
execute arbitrary code. (CVE-2022-2200, CVE-2022-31736, CVE-2022-31737,
CVE-2022-31738, CVE-2022-31740, CVE-2022-31741, CVE-2022-31742,
CVE-2022-31744, CVE-2022-31747, CVE-2022-34468, CVE-2022-34470,
CVE-2022-34479, CVE-2022-34481, CVE-2022-34484)

It was discovered that an unavailable PAC file caused OCSP requests to
be blocked, resulting in incorrect error pages being displayed.
(CVE-2022-34472)

It was discovered that the Braille space character could be used to
cause Thunderbird to display the wrong sender address for signed messages.
An attacker could potentially exploit this to trick the user into
believing a message had been sent from somebody they trusted.
(CVE-2022-1834)

It was discovered that Thunderbird would consider an email with a
mismatched OpenPGP signature date as valid. An attacker could potentially
exploit this by replaying an older message in order to trick the user into
believing that the statements in the message are current. (CVE-2022-2226)

Affected Software/OS:
'thunderbird' package(s) on Ubuntu 18.04, Ubuntu 20.04, Ubuntu 21.10, Ubuntu 22.04.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-1834
https://bugzilla.mozilla.org/show_bug.cgi?id=1767816
https://www.mozilla.org/security/advisories/mfsa2022-22/
Common Vulnerability Exposure (CVE) ID: CVE-2022-2200
https://bugzilla.mozilla.org/show_bug.cgi?id=1771381
https://www.mozilla.org/security/advisories/mfsa2022-24/
https://www.mozilla.org/security/advisories/mfsa2022-25/
https://www.mozilla.org/security/advisories/mfsa2022-26/
Common Vulnerability Exposure (CVE) ID: CVE-2022-2226
https://bugzilla.mozilla.org/show_bug.cgi?id=1775441
Common Vulnerability Exposure (CVE) ID: CVE-2022-31736
https://bugzilla.mozilla.org/show_bug.cgi?id=1735923
https://www.mozilla.org/security/advisories/mfsa2022-20/
https://www.mozilla.org/security/advisories/mfsa2022-21/
Common Vulnerability Exposure (CVE) ID: CVE-2022-31737
https://bugzilla.mozilla.org/show_bug.cgi?id=1743767
Common Vulnerability Exposure (CVE) ID: CVE-2022-31738
https://bugzilla.mozilla.org/show_bug.cgi?id=1756388
Common Vulnerability Exposure (CVE) ID: CVE-2022-31740
https://bugzilla.mozilla.org/show_bug.cgi?id=1766806
Common Vulnerability Exposure (CVE) ID: CVE-2022-31741
https://bugzilla.mozilla.org/show_bug.cgi?id=1767590
Common Vulnerability Exposure (CVE) ID: CVE-2022-31742
https://bugzilla.mozilla.org/show_bug.cgi?id=1730434
Common Vulnerability Exposure (CVE) ID: CVE-2022-31744
https://bugzilla.mozilla.org/show_bug.cgi?id=1757604
Common Vulnerability Exposure (CVE) ID: CVE-2022-31747
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1760765%2C1765610%2C1766283%2C1767365%2C1768559%2C1768734
Common Vulnerability Exposure (CVE) ID: CVE-2022-34468
https://bugzilla.mozilla.org/show_bug.cgi?id=1768537
Common Vulnerability Exposure (CVE) ID: CVE-2022-34470
https://bugzilla.mozilla.org/show_bug.cgi?id=1765951
Common Vulnerability Exposure (CVE) ID: CVE-2022-34472
https://bugzilla.mozilla.org/show_bug.cgi?id=1770123
Common Vulnerability Exposure (CVE) ID: CVE-2022-34479
https://bugzilla.mozilla.org/show_bug.cgi?id=1745595
Common Vulnerability Exposure (CVE) ID: CVE-2022-34481
https://bugzilla.mozilla.org/show_bug.cgi?id=1497246
Common Vulnerability Exposure (CVE) ID: CVE-2022-34484
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1763634%2C1772651
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.