VulnerabilityModified
CVE-2017-7829
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient.
MEDIUM 5.3EPSS 1.80%
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mozilla/thunderbird · redhat/enterprise linux aus · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation · debian/debian linux · canonical/ubuntu linux
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/102258Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040123Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0061Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1423432Exploit, Issue Tracking, Patch
- https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3529-1/Third Party Advisory
- https://www.debian.org/security/2017/dsa-4075Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-30/Vendor Advisory
- http://www.securityfocus.com/bid/102258Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040123Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0061Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1423432Exploit, Issue Tracking, Patch
- https://lists.debian.org/debian-lts-announce/2017/12/msg00026.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3529-1/Third Party Advisory
- https://www.debian.org/security/2017/dsa-4075Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-30/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.