CVE-2022-2226

high
Published 2022-07-01 Β· Modified 2022-06-30
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2022:5470: thunderbird security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid CVSS v3: 6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7thunderbird-0:91.11.0-2.el7_9RHSA-2022:54802022-07-01T00:00:00Z Red Hat Enterprise Linux 8thunderbird-0:91.11.0-2.el8_6RHSA-2022:54702022-06-30T00:00:00Z Red Hat…

Description

Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid

CVSS v3: 6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7thunderbird-0:91.11.0-2.el7_9RHSA-2022:54802022-07-01T00:00:00Z
Red Hat Enterprise Linux 8thunderbird-0:91.11.0-2.el8_6RHSA-2022:54702022-06-30T00:00:00Z
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionsthunderbird-0:91.11.0-2.el8_1RHSA-2022:54782022-06-30T00:00:00Z
Red Hat Enterprise Linux 8.2 Extended Update Supportthunderbird-0:91.11.0-2.el8_2RHSA-2022:54752022-07-01T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportthunderbird-0:91.11.0-2.el8_4RHSA-2022:54732022-06-30T00:00:00Z
Red Hat Enterprise Linux 9thunderbird-0:91.11.0-2.el9_0RHSA-2022:54822022-07-01T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6thunderbirdOut of support scope

Apply commands

bash fix
Apply RHSA-2022:5480 for Red Hat Enterprise Linux 7
yum update -y thunderbird
# or:
dnf upgrade -y thunderbird

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
debian debianbookwormfixed1:91.11.0-1
debian debianbullseyefixed1:91.11.0-1~deb11u1
debian debianforkyfixed1:91.11.0-1
debian debiansidfixed1:91.11.0-1
debian debiantrixiefixed1:91.11.0-1
almalinux almalinux9fixedthunderbird-91.11.0-2.el9_0.alma.aarch64.rpm
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.