SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-7829

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient.

MEDIUM 5.3EPSS 1.80%

Does this matter?

Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.

Description

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.80% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
mozilla/thunderbird · redhat/enterprise linux aus · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation · debian/debian linux · canonical/ubuntu linux
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.