By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbird | Aug 22, 2024 | May 22, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | May 22, 2020 | May 22, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 22, 2020 |
| Centos_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird | May 12, 2020 | May 11, 2020 |
| Debian | — | Upgrade thunderbird | May 11, 2020 | May 11, 2020 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird. | Jun 15, 2020 | May 22, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.8 | May 6, 2020 | May 5, 2020 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade mail/thunderbird to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4 | Jan 19, 2021 | May 22, 2020 |
| Oracle_linux | — | Upgrade thunderbird | Jun 19, 2020 | May 5, 2020 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceNo solution existsUpgrade thunderbird | May 12, 2020 | May 11, 2020 |
| Suse | — | Upgrade mozillathunderbird-translations-commonUpgrade mozillathunderbirdUpgrade mozillathunderbird-translations-other | May 10, 2020 | May 10, 2020 |
| Ubuntu | — | Upgrade thunderbird | May 27, 2020 | May 10, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub